Ultrajson Project maintains a specialized JSON parsing library that, despite a narrow product scope, is embedded across numerous Python applications and data-processing pipelines throughout the ecosystem. Its vulnerability profile centers on a single product, ultrajson, and recurs through memory-safety and numeric-handling weakness classes including memory-release failures, out-of-bounds writes, double frees, and integer overflows that are characteristic of performance-optimized C implementations. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultrajson Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32875HIGH UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop throug | Mar 20, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-32874HIGH UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing larg | Mar 20, 2026 | 7.5 | 29 | NO | NO |
CVE-2022-31116HIGH UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings tha | Jul 5, 2022 | 7.5 | 27 | NO | NO |
CVE-2026-54911MEDIUM UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes | Jun 22, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-44660HIGH UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operatio | May 27, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-31117MEDIUM UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string d | Jul 5, 2022 | 5.9 | 23 | NO | NO |
CVE-2021-45958MEDIUM UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of ind | Jan 1, 2022 | 5.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultrajson Project.
Media articles that mention a CVE ID that affects a product developed by Ultrajson Project — matched by CVE ID, not by vendor name.