<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:11:24 +0000</lastBuildDate>
    <item>
      <title>BREW-magic-wormhole-CVE-2026-54911 — UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()</title>
      <link>https://cve.radiocsirt.org/vuln/brew-magic-wormhole-cve-2026-54911</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: magic-wormhole&lt;/p&gt;
&lt;p&gt;### Summary
`ujson.dumps()` (or `ujson.dump()` or `ujson.encode()`) have a `reject_bytes=False` option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The expected behavior is that for `x` being any bytes string, `x == ujson.loads(ujson.dumps(x, reject_bytes=False)).encode(errors=&amp;#34;surrogatepass&amp;#34;)` should always either be true or `ujson.dumps()` will throw an exception. In reality, some strings which should&amp;#39;ve been errors are silently rewritten as other strings:&lt;/p&gt;
&lt;p&gt;* Invalid continuation bytes are replaced with valid ones: `b&amp;#39;\xcf\x13&amp;#39;` -&amp;gt; `b&amp;#39;\xcf\x93&amp;#39;`
* Unterminated sequence completes the sequence: `b&amp;#39;\xc3&amp;#39;` -&amp;gt; `b&amp;#39;\xc3\x80&amp;#39;`
* ... or leads to reading past the end of string: `b&amp;#39;\xf0\x90\x94&amp;#39;` -&amp;gt; `b&amp;#34;\xf0\x90\x94\x80inxcontrib&amp;#39;&amp;#34;`&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An application relying on reject_bytes=False for UTF-8 handling may experience:&lt;/p&gt;
&lt;p&gt;- Data integrity issues
- Experience validation bypass if said validation occurs before serialisation&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;The missing/broken UTF-8 validation checks were added/fixed in https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf. We recommend upgrading to [UltraJSON 5.13.0](https://github.com/ultrajson/ultrajson/releases/tag/5.13.0).&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Decoding bytes to strings in Python before passing them to `ujson.dumps()` avoids this…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: magic-wormhole&lt;/p&gt;
&lt;p&gt;### Summary
`ujson.dumps()` (or `ujson.dump()` or `ujson.encode()`) have a `reject_bytes=False` option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The expected behavior is that for `x` being any bytes string, `x == ujson.loads(ujson.dumps(x, reject_bytes=False)).encode(errors=&amp;#34;surrogatepass&amp;#34;)` should always either be true or `ujson.dumps()` will throw an exception. In reality, some strings which should&amp;#39;ve been errors are silently rewritten as other strings:&lt;/p&gt;
&lt;p&gt;* Invalid continuation bytes are replaced with valid ones: `b&amp;#39;\xcf\x13&amp;#39;` -&amp;gt; `b&amp;#39;\xcf\x93&amp;#39;`
* Unterminated sequence completes the sequence: `b&amp;#39;\xc3&amp;#39;` -&amp;gt; `b&amp;#39;\xc3\x80&amp;#39;`
* ... or leads to reading past the end of string: `b&amp;#39;\xf0\x90\x94&amp;#39;` -&amp;gt; `b&amp;#34;\xf0\x90\x94\x80inxcontrib&amp;#39;&amp;#34;`&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An application relying on reject_bytes=False for UTF-8 handling may experience:&lt;/p&gt;
&lt;p&gt;- Data integrity issues
- Experience validation bypass if said validation occurs before serialisation&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;The missing/broken UTF-8 validation checks were added/fixed in https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf. We recommend upgrading to [UltraJSON 5.13.0](https://github.com/ultrajson/ultrajson/releases/tag/5.13.0).&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Decoding bytes to strings in Python before passing them to `ujson.dumps()` avoids this…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-magic-wormhole-cve-2026-54911</guid>
    </item>
    <item>
      <title>CVE-2026-54911 — UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54911</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; ultrajson&lt;/p&gt;
&lt;p&gt;UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues. This vulnerability is fixed in 5.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; ultrajson&lt;/p&gt;
&lt;p&gt;UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues. This vulnerability is fixed in 5.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54911</guid>
    </item>
    <item>
      <title>GHSA-3j69-69wj-xqx2 — UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3j69-69wj-xqx2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ujson&lt;/p&gt;
&lt;p&gt;### Summary
`ujson.dumps()` (or `ujson.dump()` or `ujson.encode()`) have a `reject_bytes=False` option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The expected behavior is that for `x` being any bytes string, `x == ujson.loads(ujson.dumps(x, reject_bytes=False)).encode(errors=&amp;#34;surrogatepass&amp;#34;)` should always either be true or `ujson.dumps()` will throw an exception. In reality, some strings which should&amp;#39;ve been errors are silently rewritten as other strings:&lt;/p&gt;
&lt;p&gt;* Invalid continuation bytes are replaced with valid ones: `b&amp;#39;\xcf\x13&amp;#39;` -&amp;gt; `b&amp;#39;\xcf\x93&amp;#39;`
* Unterminated sequence completes the sequence: `b&amp;#39;\xc3&amp;#39;` -&amp;gt; `b&amp;#39;\xc3\x80&amp;#39;`
* ... or leads to reading past the end of string: `b&amp;#39;\xf0\x90\x94&amp;#39;` -&amp;gt; `b&amp;#34;\xf0\x90\x94\x80inxcontrib&amp;#39;&amp;#34;`&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An application relying on reject_bytes=False for UTF-8 handling may experience:&lt;/p&gt;
&lt;p&gt;- Data integrity issues
- Experience validation bypass if said validation occurs before serialisation&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;The missing/broken UTF-8 validation checks were added/fixed in https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf. We recommend upgrading to [UltraJSON 5.13.0](https://github.com/ultrajson/ultrajson/releases/tag/5.13.0).&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Decoding bytes to strings in Python before passing them to `ujson.dumps()` avoids this…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ujson&lt;/p&gt;
&lt;p&gt;### Summary
`ujson.dumps()` (or `ujson.dump()` or `ujson.encode()`) have a `reject_bytes=False` option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The expected behavior is that for `x` being any bytes string, `x == ujson.loads(ujson.dumps(x, reject_bytes=False)).encode(errors=&amp;#34;surrogatepass&amp;#34;)` should always either be true or `ujson.dumps()` will throw an exception. In reality, some strings which should&amp;#39;ve been errors are silently rewritten as other strings:&lt;/p&gt;
&lt;p&gt;* Invalid continuation bytes are replaced with valid ones: `b&amp;#39;\xcf\x13&amp;#39;` -&amp;gt; `b&amp;#39;\xcf\x93&amp;#39;`
* Unterminated sequence completes the sequence: `b&amp;#39;\xc3&amp;#39;` -&amp;gt; `b&amp;#39;\xc3\x80&amp;#39;`
* ... or leads to reading past the end of string: `b&amp;#39;\xf0\x90\x94&amp;#39;` -&amp;gt; `b&amp;#34;\xf0\x90\x94\x80inxcontrib&amp;#39;&amp;#34;`&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An application relying on reject_bytes=False for UTF-8 handling may experience:&lt;/p&gt;
&lt;p&gt;- Data integrity issues
- Experience validation bypass if said validation occurs before serialisation&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;The missing/broken UTF-8 validation checks were added/fixed in https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf. We recommend upgrading to [UltraJSON 5.13.0](https://github.com/ultrajson/ultrajson/releases/tag/5.13.0).&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Decoding bytes to strings in Python before passing them to `ujson.dumps()` avoids this…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3j69-69wj-xqx2</guid>
    </item>
  </channel>
</rss>
