VDB
KO

PYSEC-2022-25

Details

UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / ujson
Introduced in: 4.0.2 Fixed in: 5.1.0
Fix pip install --upgrade 'ujson>=5.1.0'

References