CVE-2026-32875: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-32875 is an integer overflow vulnerability in UltraJSON (ujson), a fast JSON encoder/decoder written in C with Python bindings, that leads to a buffer overflow or infinite loop when handling large or negative indent parameter values. It affects ujson versions 5.1.0 through 5.11.0 (pip package). The vulnerability was independently discovered by researchers @coco1629, @EthanKim88, and @vmfunc, with the original bug report filed on February 6, 2026, and the security advisory published on March 17, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an integer overflow/underflow (CWE-190) in the C-level indentation memory reservation logic within ujsonenc.c. When ujson.dumps() is called with a large positive indent, the product of indent * nest_depth overflows a 32-bit integer (int), causing the required output buffer size to be underestimated and resulting in an out-of-bounds write (CWE-787). For large negative indent values, a size_t underflow causes the buffer up-sizer to enter an infinite loop (CWE-835) searching for a power-of-two buffer size that cannot fit in size_t. The fix in commit 486bd45 promotes the offending integer types to ptrdiff_t, skips the indentation code path for negative indents, and caps the indent parameter at 1000. Exploitation requires that an attacker control the indent parameter passed to ujson.dump(), ujson.dumps(), or ujson.encode() (GitHub Advisory, Patch Commit).

Impact

Successful exploitation results in a denial of service (DoS) — either a Python interpreter crash via segmentation fault (when indent * nest_depth > INT32_MAX) or an application hang via infinite loop (when a large negative indent is used with nested input). There is no impact on confidentiality or data integrity; the vulnerability is purely an availability issue. Downstream products incorporating ujson, including IBM API Connect, IBM Cloud Pak for Security (QRadar Suite), and IBM Cloudera Data Platform Private Cloud Base, are also affected (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no standalone weaponized exploit exists — the referenced advisory code snippet is a local bug illustration requiring a real ujson deployment to reproduce. The EPSS score is approximately 0.038% (Feedly data) to 0.072% (GitHub Advisory), placing it in a low exploitation probability range. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys and Nessus (GitHub Advisory).

Exploitation steps

  1. Identify vulnerable services: Locate Python web services or APIs that use ujson versions 5.1.0–5.11.0 and expose an endpoint where the caller can influence the indent parameter passed to ujson.dump(), ujson.dumps(), or ujson.encode().
  2. Craft a crash payload (segfault path): Send a request that causes the service to call ujson.dumps(deeply_nested_object, indent=2**30) — where the product of the indent value and the nesting depth exceeds INT32_MAX. For example, an object nested 1000 levels deep with indent=2**30 is sufficient.
  3. Craft an infinite loop payload (negative indent path): If the service uses a fixed large negative indent (e.g., indent=-200) or allows negative indent values, send a request with nested JSON input (at least one level deep) to trigger the size_t underflow and hang the process.
  4. Achieve denial of service: The Python interpreter crashes (segfault) or the process hangs indefinitely, making the service unavailable to legitimate users (GitHub Advisory, Bug Report).

Indicators of compromise

  • Logs: Application logs showing unexpected process termination with a segmentation fault signal (SIGSEGV) from the Python interpreter; absence of a clean shutdown log entry.
  • Process: Python worker processes that become unresponsive or consume 100% CPU without completing requests, particularly those handling JSON serialization endpoints.
  • Application Behavior: API endpoints returning no response or timing out on requests that include an indent parameter with very large positive or negative values.
  • System: Core dump files generated by the Python process in the application working directory following a segfault (GitHub Advisory).

Mitigation and workarounds

Upgrade ujson to version 5.12.0 or later, which fixes the integer overflow by promoting affected types to ptrdiff_t and capping the indent parameter at 1000 (Patch Commit). If immediate upgrade is not possible, restrict the indent parameter to reasonably small non-negative values (below 2**31 / max_recursion_depth) and never allow untrusted user input to control the indent argument. Services using a fixed negative indent should also be considered at risk and should migrate to a non-negative or zero indent. IBM has released patches for affected products including API Connect and QRadar Suite Software (IBM API Connect Advisory, IBM QRadar Advisory).

Community reactions

Red Hat triaged the issue at high severity in their Bugzilla tracker and assigned it to the Product Security DevOps Team for remediation across affected packages (Red Hat Bugzilla). IBM issued security bulletins for multiple affected products including API Connect, QRadar Suite Software, and Cloudera Data Platform Private Cloud Base (IBM API Connect Advisory). Ubuntu issued security notice USN-8219-1 and Mageia issued advisory MGASA-2026-0073 addressing the vulnerability in their respective distributions. Community discussion on Bluesky and Linux security forums noted the straightforward nature of the fix and the importance of input validation for serialization parameters.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

ujson

Affected

sid

ujson: 5.13.0-1

Fixed

trixie

ujson

Affected

Ubuntu

Fixed

bionic (esm-apps)

ujson

Not Affected

devel

ujson

Affected

focal (esm-apps)

ujson

Not Affected

jammy

ujson

Affected

jammy (esm-apps)

ujson: 5.1.0-1ubuntu0.1~esm2

Fixed

noble

ujson

Affected

noble (esm-apps)

ujson: 5.9.0-1ubuntu0.1~esm1

Fixed

questing

ujson: 5.10.0-1ubuntu0.1

Fixed

RHEL / CentOS

Unknown

Alpine

Fixed

edge

py3-ujson: 5.12.0-r0

Fixed

v3.23

py3-ujson: 5.12.0-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management