THREAT OPS › Threat News › UltraJSON v5.13.0-6-g733f9e1 Length-Boundary Violation Causes Out-of-Bounds Read During Incomplete JSON Parsing
UltraJSON v5.13.0-6-g733f9e1 Length-Boundary Violation Causes Out-of-Bounds Read During Incomplete JSON Parsing
<p>Posted by Ron E on Aug 26</p>UltraJSON contains an out-of-bounds read in its native C JSON decoder when<br /> processing certain incomplete JSON values supplied through an explicitly<br /> length-bounded input buffer.<br /> <br /> The affected native entry point, JSON_DecodeObject(), accepts both a buffer<br /> pointer and an explicit buffer length:<br /> <br /> JSON_DecodeObject(<br /> JSO
Original source: https://seclists.org/fulldisclosure/2026/Aug/106