Executive brief
UltraJSON is a high-performance library used by Python applications to process data in the JSON format. A flaw in how it handles certain text encoding settings allows malformed or incomplete data to be silently modified rather than rejected. This can lead to data corruption or allow attackers to bypass security filters that check data before it is saved or processed.
Technical details
A vulnerability exists in UltraJSON's C-based JSON encoder (ujson.dumps, ujson.dump, and ujson.encode) when the 'reject_bytes=False' parameter is enabled. The root cause is improper validation of UTF-8 sequences, including off-by-one errors in sequence detection, missing checks for codepoints exceeding the Unicode maximum, and failure to validate continuation bytes. An attacker can provide malformed or truncated UTF-8 sequences that the library silently rewrites into valid but unintended Unicode characters. This behavior can result in data integrity issues or the bypass of security sanitization logic that occurred prior to serialization. The issue is fixed in version 5.13.0 by tightening UTF-8 validation logic.
Affected products
- ultrajson UltraJSON (ujson) < 5.13.0
Timeline
- 2026-04-24: other: Initial fix commit authored
- 2026-06-14: patched: Version 5.13.0 released
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-06-22: disclosed: CVE published to NVD