Advisories ยป MGASA-2026-0073

Updated python-ujson packages fix security vulnerabilities

Publication date: 29 Mar 2026
Modification date: 29 Mar 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-32874 , CVE-2026-32875

Description

CVE-2026-32874 ujson 5.4.0 to 5.11.0 inclusive contains an accumulating
memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1])
integers.
ujson 5.4.0 to 5.11.0 has an integer overflow while handling a large indent
which leads to a buffer overflow or infinite loop.
                

References

SRPMS

9/core