Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32874

29
FAUCET Score

CVE-2026-32874 describes an accumulating memory leak in UltraJSON versions 5.4.0 through 5.11.0, impacting services that parse untrusted JSON inputs containing large integers. This vulnerability, with a CVSS score of 7.5 (High), allows a remote attacker to trigger a denial of service through memory exhaustion with low attack complexity. The leak occurs irrespective of parsing success, meaning any sized leak can be achieved per malicious JSON payload. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.4.0, < 5.12.0CPE matchmatch criteria
cpe:2.3:a:ultrajson_project:ultrajson:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
38.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0048 is in the 17th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: ujsonFixed in: 5.12.0
ubuntupatch availablevia ubuntu_usn
Product: ujson (questing)Fixed in: 5.10.0-1ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: ujson (resolute)Fixed in: 5.11.0-3ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: ujson (jammy)Fixed in: 5.1.0-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: ujson (noble)Fixed in: 5.9.0-1ubuntu0.1~esm1
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: python-ujson
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 17.1Fixed in: python-ujson
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 18.0Fixed in: python-ujson

Vendor Advisories (3)

ubuntuUSN-8219-1

UltraJSON vulnerabilities

Apr 28, 2026
redhatCVE-2026-32874Important

UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers

Mar 20, 2026
pipGHSA-wgvc-ghv9-3pmmhigh

UltraJSON has a Memory Leak parsing large integers allows DoS

Mar 18, 2026

References

access.redhat.com / security/cve/CVE-2026-32874
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-32874.json
github.com / ultrajson/ultrajson/commit/4baeb950df780092bd3c89fc702a868e99a3a1d2
Patch
github.com / ultrajson/ultrajson/releases/tag/5.12.0
ProductRelease Notes
github.com / ultrajson/ultrajson/security/advisories/GHSA-wgvc-ghv9-3pmm
Vendor Advisory