
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32875 is an integer overflow vulnerability in UltraJSON (ujson), a fast JSON encoder/decoder written in C with Python bindings, that leads to a buffer overflow or infinite loop when handling large or negative indent parameter values. It affects ujson versions 5.1.0 through 5.11.0 (pip package). The vulnerability was independently discovered by researchers @coco1629, @EthanKim88, and @vmfunc, with the original bug report filed on February 6, 2026, and the security advisory published on March 17, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an integer overflow/underflow (CWE-190) in the C-level indentation memory reservation logic within ujsonenc.c. When ujson.dumps() is called with a large positive indent, the product of indent * nest_depth overflows a 32-bit integer (int), causing the required output buffer size to be underestimated and resulting in an out-of-bounds write (CWE-787). For large negative indent values, a size_t underflow causes the buffer up-sizer to enter an infinite loop (CWE-835) searching for a power-of-two buffer size that cannot fit in size_t. The fix in commit 486bd45 promotes the offending integer types to ptrdiff_t, skips the indentation code path for negative indents, and caps the indent parameter at 1000. Exploitation requires that an attacker control the indent parameter passed to ujson.dump(), ujson.dumps(), or ujson.encode() (GitHub Advisory, Patch Commit).
Successful exploitation results in a denial of service (DoS) — either a Python interpreter crash via segmentation fault (when indent * nest_depth > INT32_MAX) or an application hang via infinite loop (when a large negative indent is used with nested input). There is no impact on confidentiality or data integrity; the vulnerability is purely an availability issue. Downstream products incorporating ujson, including IBM API Connect, IBM Cloud Pak for Security (QRadar Suite), and IBM Cloudera Data Platform Private Cloud Base, are also affected (GitHub Advisory, Red Hat Bugzilla).
No confirmed in-the-wild exploitation has been observed, and no standalone weaponized exploit exists — the referenced advisory code snippet is a local bug illustration requiring a real ujson deployment to reproduce. The EPSS score is approximately 0.038% (Feedly data) to 0.072% (GitHub Advisory), placing it in a low exploitation probability range. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys and Nessus (GitHub Advisory).
indent parameter passed to ujson.dump(), ujson.dumps(), or ujson.encode().ujson.dumps(deeply_nested_object, indent=2**30) — where the product of the indent value and the nesting depth exceeds INT32_MAX. For example, an object nested 1000 levels deep with indent=2**30 is sufficient.indent=-200) or allows negative indent values, send a request with nested JSON input (at least one level deep) to trigger the size_t underflow and hang the process.indent parameter with very large positive or negative values.Upgrade ujson to version 5.12.0 or later, which fixes the integer overflow by promoting affected types to ptrdiff_t and capping the indent parameter at 1000 (Patch Commit). If immediate upgrade is not possible, restrict the indent parameter to reasonably small non-negative values (below 2**31 / max_recursion_depth) and never allow untrusted user input to control the indent argument. Services using a fixed negative indent should also be considered at risk and should migrate to a non-negative or zero indent. IBM has released patches for affected products including API Connect and QRadar Suite Software (IBM API Connect Advisory, IBM QRadar Advisory).
Red Hat triaged the issue at high severity in their Bugzilla tracker and assigned it to the Product Security DevOps Team for remediation across affected packages (Red Hat Bugzilla). IBM issued security bulletins for multiple affected products including API Connect, QRadar Suite Software, and Cloudera Data Platform Private Cloud Base (IBM API Connect Advisory). Ubuntu issued security notice USN-8219-1 and Mageia issued advisory MGASA-2026-0073 addressing the vulnerability in their respective distributions. Community discussion on Bluesky and Linux security forums noted the straightforward nature of the fix and the importance of input validation for serialization parameters.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
ujson
devel
ujson
focal (esm-apps)
ujson
jammy
ujson
jammy (esm-apps)
ujson: 5.1.0-1ubuntu0.1~esm2
noble
ujson
noble (esm-apps)
ujson: 5.9.0-1ubuntu0.1~esm1
questing
ujson: 5.10.0-1ubuntu0.1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."