CVE-2026-32874: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-32874 is a memory leak vulnerability in UltraJSON (ujson), a fast JSON encoder/decoder written in C with Python bindings, that enables denial-of-service attacks. Versions 5.4.0 through 5.11.0 inclusive are affected; the issue was discovered by Cameron Criswell (Skevros) via coverage-guided fuzzing (libFuzzer + AddressSanitizer) and disclosed on March 17, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is a missing memory deallocation (CWE-401 / CWE-772) in the C-level JSON integer parsing routine Object_newIntegerFromString in src/ujson/python/JSONtoObj.c. When parsing integers outside the range [-2^63, 2^64 - 1], the function allocates a buffer (PyObject_Malloc) to hold the string representation of the integer but fails to free it before returning, causing a per-call memory leak equal to the length of the integer string plus one NULL byte. The leak occurs regardless of whether parsing succeeds or raises a ValueError due to exceeding sys.get_int_max_str_digits(), meaning an attacker can engineer arbitrarily large leaks per request if no payload size limit is enforced. The fix in commit 4baeb950 adds a PyObject_Free(buf) call after PyLong_FromString (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation causes cumulative, unbounded memory exhaustion on the host process, leading to denial of service. Any Python service that passes untrusted JSON input to ujson.load(), ujson.loads(), or ujson.decode() is at risk; there is no confidentiality or integrity impact. Downstream products incorporating ujson 5.4.0–5.11.0 — including IBM API Connect, IBM Cloud Pak for Security (QRadar Suite), and IBM Cloudera Data Platform Private Cloud Base — are also affected (GitHub Advisory, IBM Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported. The vulnerability is trivially exploitable by any unauthenticated network attacker who can submit JSON payloads to an affected service, requiring no privileges or user interaction. The EPSS score is approximately 0.048% (0.077% per GitHub Advisory), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate a network-accessible service that uses ujson 5.4.0–5.11.0 to parse untrusted JSON input (e.g., a REST API endpoint accepting JSON bodies).
  2. Craft malicious payload: Construct a JSON document containing one or more integers larger than 2^64 - 1 (e.g., {"n": 18446744073709551616} or a string of 10,000+ digit characters like "9" * 10000).
  3. Send repeated requests: Repeatedly submit the crafted payload to the target endpoint. Each request causes the server process to leak memory proportional to the integer string length without releasing it.
  4. Exhaust memory: With no payload size limit in place, continue sending requests until the server's available memory is exhausted, causing the process to crash or become unresponsive, achieving denial of service (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: High volume of HTTP requests to JSON-accepting endpoints containing abnormally large integer values (e.g., integers exceeding 20 digits) in the request body.
  • Process: Steadily increasing RSS/heap memory usage of the Python process hosting ujson without corresponding increase in legitimate workload; eventual OOM-killer events or process crashes.
  • Logs: Application logs showing repeated ValueError: integer string conversion exceptions from ujson alongside high request rates from a single source IP; OS-level OOM messages in /var/log/syslog or dmesg referencing the affected process.

Mitigation and workarounds

Upgrade ujson to version 5.12.0 or later, which contains the fix (commit 4baeb950). There are no configuration-based workarounds; the vendor explicitly states that upgrading is the only remediation. As a defense-in-depth measure, enforce strict payload size limits at the API gateway or web server layer to reduce the per-request leak magnitude. IBM has released updated advisories for affected products (API Connect, QRadar Suite, Cloudera Data Platform) that incorporate the patched ujson version (GitHub Advisory, ujson Release, IBM Advisory).

Community reactions

Red Hat triaged the issue as high severity and opened a Bugzilla tracking entry (Bug 2449411) covering multiple dependent packages (Red Hat Bugzilla). Ubuntu issued security notice USN-8219-1 and Fedora/Mageia published security advisories addressing the vulnerability in their respective python-ujson packages. IBM published security bulletins for API Connect, QRadar Suite Software, and Cloudera Data Platform Private Cloud Base (IBM Advisory). No significant social media controversy or notable researcher commentary beyond standard disclosure channels has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

ujson

Affected

sid

ujson: 5.13.0-1

Fixed

trixie

ujson

Affected

Ubuntu

Fixed

bionic (esm-apps)

ujson

Not Affected

devel

ujson

Affected

focal (esm-apps)

ujson

Not Affected

jammy

ujson

Not Affected

jammy (esm-apps)

ujson

Not Affected

noble

ujson

Affected

noble (esm-apps)

ujson: 5.9.0-1ubuntu0.1~esm1

Fixed

questing

ujson: 5.10.0-1ubuntu0.1

Fixed

RHEL / CentOS

Unknown

Alpine

Fixed

edge

py3-ujson: 5.12.0-r0

Fixed

v3.23

py3-ujson: 5.12.0-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management