{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32875.json"
      }
    ],
    "title": "ultrajson: UltraJSON: Denial of Service via large indent parameter in JSON serialization",
    "tracking": {
      "current_release_date": "2026-06-30T04:06:50+00:00",
      "generator": {
        "date": "2026-06-30T04:06:50+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-32875",
      "initial_release_date": "2026-03-20T01:35:23.362000+00:00",
      "revision_history": [
        {
          "date": "2026-03-20T01:35:23.362000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-23T17:18:15+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T04:06:50+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 16.2",
                "product": {
                  "name": "Red Hat OpenStack Platform 16.2",
                  "product_id": "red_hat_openstack_platform_16.2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:16.2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 16.2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 17.1",
                "product": {
                  "name": "Red Hat OpenStack Platform 17.1",
                  "product_id": "red_hat_openstack_platform_17.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:17.1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 17.1"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 18.0",
                "product": {
                  "name": "Red Hat OpenStack Platform 18.0",
                  "product_id": "red_hat_openstack_platform_18.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:18.0"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 18.0"
          },
          {
            "category": "product_version",
            "name": "python3-ujson",
            "product": {
              "name": "python3-ujson",
              "product_id": "python3-ujson",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/python3-ujson"
              }
            }
          },
          {
            "category": "product_version",
            "name": "python-ujson.src",
            "product": {
              "name": "python-ujson.src",
              "product_id": "python-ujson.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/python-ujson?arch=src"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python-ujson.src as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:python-ujson.src"
        },
        "product_reference": "python-ujson.src",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-ujson as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:python3-ujson"
        },
        "product_reference": "python3-ujson",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-ujson as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:python3-ujson"
        },
        "product_reference": "python3-ujson",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python-ujson.src as a component of Red Hat OpenStack Platform 18.0",
          "product_id": "red_hat_openstack_platform_18.0:python-ujson.src"
        },
        "product_reference": "python-ujson.src",
        "relates_to_product_reference": "red_hat_openstack_platform_18.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-32875",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "discovery_date": "2026-03-20T03:02:30.994308+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_openstack_platform_16.2:python-ujson.src",
            "red_hat_openstack_platform_16.2:python3-ujson",
            "red_hat_openstack_platform_17.1:python3-ujson",
            "red_hat_openstack_platform_18.0:python-ujson.src"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2449400"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in UltraJSON, a fast JSON encoder and decoder. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing a specially crafted large positive or negative indent value to the JSON serialization functions. This can lead to a buffer overflow, causing the Python interpreter to crash, or an infinite loop, making the application unresponsive. The issue stems from an integer overflow or underflow during memory allocation for indentation.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "ultrajson: UltraJSON: Denial of Service via large indent parameter in JSON serialization",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an IMPORTANT denial of service flaw in UltraJSON, affecting Red Hat products that utilize `python-ujson`, including various Community Projects and Red Hat OpenStack Platform. The vulnerability arises when applications process untrusted input that controls the `indent` parameter in JSON serialization functions, potentially leading to a Python interpreter crash or an infinite loop. Exploitation requires a service to explicitly expose the `indent` parameter to untrusted users without proper validation.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_openstack_platform_16.2:python-ujson.src",
          "red_hat_openstack_platform_16.2:python3-ujson",
          "red_hat_openstack_platform_17.1:python3-ujson",
          "red_hat_openstack_platform_18.0:python-ujson.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-32875"
        },
        {
          "category": "external",
          "summary": "RHBZ#2449400",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449400"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-32875",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32875"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-32875",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32875"
        },
        {
          "category": "external",
          "summary": "https://github.com/ultrajson/ultrajson/commit/486bd4553dc471a1de11613bc7347a6b318e37ea",
          "url": "https://github.com/ultrajson/ultrajson/commit/486bd4553dc471a1de11613bc7347a6b318e37ea"
        },
        {
          "category": "external",
          "summary": "https://github.com/ultrajson/ultrajson/issues/700",
          "url": "https://github.com/ultrajson/ultrajson/issues/700"
        },
        {
          "category": "external",
          "summary": "https://github.com/ultrajson/ultrajson/security/advisories/GHSA-c8rr-9gxc-jprv",
          "url": "https://github.com/ultrajson/ultrajson/security/advisories/GHSA-c8rr-9gxc-jprv"
        }
      ],
      "release_date": "2026-03-20T01:35:23.362000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_openstack_platform_16.2:python-ujson.src",
            "red_hat_openstack_platform_16.2:python3-ujson",
            "red_hat_openstack_platform_17.1:python3-ujson",
            "red_hat_openstack_platform_18.0:python-ujson.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openstack_platform_16.2:python-ujson.src",
            "red_hat_openstack_platform_16.2:python3-ujson",
            "red_hat_openstack_platform_17.1:python3-ujson",
            "red_hat_openstack_platform_18.0:python-ujson.src"
          ]
        }
      ],
      "title": "ultrajson: UltraJSON: Denial of Service via large indent parameter in JSON serialization"
    }
  ]
}