{"id":"CVE-2026-54911","aliases":["GHSA-3j69-69wj-xqx2","PYSEC-2026-2294"],"url":"https://o3.security/vulnerability/CVE-2026-54911","summary":"UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()","details":"UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues. This vulnerability is fixed in 5.13.0.","published":"2026-06-22T20:53:07.019Z","modified":"2026-08-12T16:41:17.543206Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":{"score":0.00371,"percentile":0.30599,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ujson","fixedVersion":"5.13.0"}],"fix":{"url":"https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf","label":"ultrajson/ultrajson@169eaf3"},"references":[{"type":"WEB","url":"https://github.com/ultrajson/ultrajson/releases/tag/5.13.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54911.json"},{"type":"ADVISORY","url":"https://github.com/ultrajson/ultrajson/security/advisories/GHSA-3j69-69wj-xqx2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54911"},{"type":"FIX","url":"https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T16:41:17.543206Z"}}