
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32874 is a memory leak vulnerability in UltraJSON (ujson), a fast JSON encoder/decoder written in C with Python bindings, that enables denial-of-service attacks. Versions 5.4.0 through 5.11.0 inclusive are affected; the issue was discovered by Cameron Criswell (Skevros) via coverage-guided fuzzing (libFuzzer + AddressSanitizer) and disclosed on March 17, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is a missing memory deallocation (CWE-401 / CWE-772) in the C-level JSON integer parsing routine Object_newIntegerFromString in src/ujson/python/JSONtoObj.c. When parsing integers outside the range [-2^63, 2^64 - 1], the function allocates a buffer (PyObject_Malloc) to hold the string representation of the integer but fails to free it before returning, causing a per-call memory leak equal to the length of the integer string plus one NULL byte. The leak occurs regardless of whether parsing succeeds or raises a ValueError due to exceeding sys.get_int_max_str_digits(), meaning an attacker can engineer arbitrarily large leaks per request if no payload size limit is enforced. The fix in commit 4baeb950 adds a PyObject_Free(buf) call after PyLong_FromString (GitHub Commit, GitHub Advisory).
Successful exploitation causes cumulative, unbounded memory exhaustion on the host process, leading to denial of service. Any Python service that passes untrusted JSON input to ujson.load(), ujson.loads(), or ujson.decode() is at risk; there is no confidentiality or integrity impact. Downstream products incorporating ujson 5.4.0–5.11.0 — including IBM API Connect, IBM Cloud Pak for Security (QRadar Suite), and IBM Cloudera Data Platform Private Cloud Base — are also affected (GitHub Advisory, IBM Advisory).
No public exploit code or in-the-wild exploitation has been reported. The vulnerability is trivially exploitable by any unauthenticated network attacker who can submit JSON payloads to an affected service, requiring no privileges or user interaction. The EPSS score is approximately 0.048% (0.077% per GitHub Advisory), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).
{"n": 18446744073709551616} or a string of 10,000+ digit characters like "9" * 10000).ValueError: integer string conversion exceptions from ujson alongside high request rates from a single source IP; OS-level OOM messages in /var/log/syslog or dmesg referencing the affected process.Upgrade ujson to version 5.12.0 or later, which contains the fix (commit 4baeb950). There are no configuration-based workarounds; the vendor explicitly states that upgrading is the only remediation. As a defense-in-depth measure, enforce strict payload size limits at the API gateway or web server layer to reduce the per-request leak magnitude. IBM has released updated advisories for affected products (API Connect, QRadar Suite, Cloudera Data Platform) that incorporate the patched ujson version (GitHub Advisory, ujson Release, IBM Advisory).
Red Hat triaged the issue as high severity and opened a Bugzilla tracking entry (Bug 2449411) covering multiple dependent packages (Red Hat Bugzilla). Ubuntu issued security notice USN-8219-1 and Fedora/Mageia published security advisories addressing the vulnerability in their respective python-ujson packages. IBM published security bulletins for API Connect, QRadar Suite Software, and Cloudera Data Platform Private Cloud Base (IBM Advisory). No significant social media controversy or notable researcher commentary beyond standard disclosure channels has been observed.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
ujson
devel
ujson
focal (esm-apps)
ujson
jammy
ujson
jammy (esm-apps)
ujson
noble
ujson
noble (esm-apps)
ujson: 5.9.0-1ubuntu0.1~esm1
questing
ujson: 5.10.0-1ubuntu0.1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."