CVE-2021-45958

MEDIUM

ultrajson < 5.2.0 - Stack-based Buffer Overflow via Indentation Handling

Title source: llm
STIX 2.1

Description

UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.

References (10)

Core 10
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/ultrajson/ultrajson/issues/501
Patch, Third Party Advisory x_refsource_confirm
https://github.com/ultrajson/ultrajson/pull/504
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/02/msg00023.html

Scores

CVSS v3 5.5
EPSS 0.0029
EPSS Percentile 52.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (6)
debian/debian_linux 9.0
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
pypi/ujson 1.34 - 5.2.0PyPI
ultrajson_project/ultrajson < 5.2.0
Published Jan 01, 2022
Tracked Since Feb 18, 2026