DEBIAN-CVE-2026-54911

Source
https://security-tracker.debian.org/tracker/CVE-2026-54911
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54911.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-54911
Upstream
Published
2026-06-22T22:16:50Z
Modified
2026-09-01T16:06:51Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues. This vulnerability is fixed in 5.13.0.

References

Affected packages

Debian:12 / ujson

Package

Name
ujson
Purl
pkg:deb/debian/ujson?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.7.0-1
5.8.0-1
5.9.0-1
5.10.0-1
5.11.0-1
5.11.0-2
5.11.0-3
5.13.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54911.json"

Debian:13 / ujson

Package

Name
ujson
Purl
pkg:deb/debian/ujson?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.10.0-1
5.11.0-1
5.11.0-2
5.11.0-3
5.13.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54911.json"

Debian:14 / ujson

Package

Name
ujson
Purl
pkg:deb/debian/ujson?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.13.0-1

Affected versions

5.*
5.10.0-1
5.11.0-1
5.11.0-2
5.11.0-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54911.json"