{"id":"PYSEC-2022-25","details":"UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.","aliases":["CVE-2021-45958","GHSA-fh56-85cw-5pq6"],"modified":"2023-11-08T04:07:24.600926Z","published":"2022-01-01T00:15:00Z","references":[{"type":"WEB","url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yaml"},{"type":"WEB","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009"},{"type":"REPORT","url":"https://github.com/ultrajson/ultrajson/issues/501"},{"type":"REPORT","url":"https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh56-85cw-5pq6"}],"affected":[{"package":{"name":"ujson","ecosystem":"PyPI","purl":"pkg:pypi/ujson"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.2"},{"fixed":"5.1.0"}]}],"versions":["4.0.2","4.1.0","4.2.0","4.3.0","5.0.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ujson/PYSEC-2022-25.yaml"}}],"schema_version":"1.7.3"}