Updated python-ujson packages fix security vulnerabilities
Publication date: 29 Mar 2026Modification date: 29 Mar 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-32874 , CVE-2026-32875
Description
CVE-2026-32874 ujson 5.4.0 to 5.11.0 inclusive contains an accumulating
memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1])
integers.
ujson 5.4.0 to 5.11.0 has an integer overflow while handling a large indent
which leads to a buffer overflow or infinite loop.
References
- https://bugs.mageia.org/show_bug.cgi?id=35258
- https://github.com/ultrajson/ultrajson/security/advisories/GHSA-wgvc-ghv9-3pmm
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FAXR2DP4Q5GMDURV7CAFQ5YGYAOMVNL/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32874
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32875
SRPMS
9/core
- python-ujson-5.7.0-1.1.mga9