Fedora has issued an advisory on March 21: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FAXR2DP4Q5GMDURV7CAFQ5YGYAOMVNL/
CVE-2026-32874 fixed by: https://github.com/ultrajson/ultrajson/commit/4baeb950df780092bd3c89fc702a868e99a3a1d2 CVE-2026-32875 fixed by: https://github.com/ultrajson/ultrajson/commit/486bd4553dc471a1de11613bc7347a6b318e37ea
Whiteboard: (none) => MGA9TOOSource RPM: (none) => python-ujson-5.10.0-2.mga10.src.rpm, python-ujson-5.7.0-1.mga9.src.rpmCVE: (none) => CVE-2026-32874, CVE-2026-32875Status comment: (none) => Fixed upstream in 5.12.0
Status comment: Fixed upstream in 5.12.0 => Fixed upstream in 5.12.0 and patches available from upstream
Thanks for the patch refs.
Assignee: bugsquad => python
The 2 patches are applied : SRPMS: python-ujson-5.7.0-1.1.mga9 RPMS: python3-ujson-5.7.0-1.1.mga9
Status comment: Fixed upstream in 5.12.0 and patches available from upstream => (none)CC: (none) => yves.brungardAssignee: python => qa-bugsWhiteboard: MGA9TOO => (none)Source RPM: python-ujson-5.10.0-2.mga10.src.rpm, python-ujson-5.7.0-1.mga9.src.rpm => python-ujson-5.7.0-1.mga9.src.rpmVersion: Cauldron => 9
Cauldron fixed with 5.12.0
MGA9-64 server Plasma Wayland on Compaq H000SB No installation issues. Ref bug 31332 for test: $ python3 testujson.py a type: <class 'dict'> b variable: <class 'str'> {"name":"Horseman","age":"21","city":"Mumbai"} { "name": "Horseman", "age": "21", "city": "Mumbai" } c variable: <class 'dict'> {'name': 'Horseman', 'age': '21', 'city': 'Mumbai'} Looks OK.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0073.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED