{"id":"PYSEC-2026-1056","summary":"Potential double free of buffer during string decoding","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nWhen an error occurs while reallocating the buffer for string decoding, the buffer gets freed twice.\n\nDue to how UltraJSON uses the internal decoder, this double free is impossible to trigger from Python.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nUsers should upgrade to UltraJSON 5.4.0.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nThere is no workaround.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [UltraJSON](http://github.com/ultrajson/ultrajson/issues)\n","aliases":["CVE-2022-31117","GHSA-fm67-cv37-96ff"],"modified":"2026-07-07T11:45:23.813437627Z","published":"2026-07-06T08:03:30.989917Z","references":[{"type":"WEB","url":"https://github.com/ultrajson/ultrajson/security/advisories/GHSA-fm67-cv37-96ff"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31117"},{"type":"WEB","url":"https://github.com/ultrajson/ultrajson/commit/9c20de0f77b391093967e25d01fb48671104b15b"},{"type":"PACKAGE","url":"https://github.com/ultrajson/ultrajson"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NAU5N4A7EUK2AMUCOLYDD5ARXAJYZBD2"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OPPU5FZP3LCTXYORFH7NHUMYA5X66IA7"},{"type":"PACKAGE","url":"https://pypi.org/project/ujson"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fm67-cv37-96ff"}],"affected":[{"package":{"name":"ujson","ecosystem":"PyPI","purl":"pkg:pypi/ujson"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.0"}]}],"versions":["1.15","1.18","1.19","1.21","1.22","1.23","1.30","1.33","1.34","1.35","1.4","1.6","1.8","1.9","2.0.0","2.0.1","2.0.2","2.0.3","3.0.0","3.1.0","3.2.0","4.0.0","4.0.1","4.0.2","4.1.0","4.2.0","4.3.0","5.0.0","5.1.0","5.2.0","5.3.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ujson/PYSEC-2026-1056.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}