Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
From https://www.cve.org/CVERecord?id=CVE-2026-44660, this is fixed in upstream release 5.12.1, which has already reached stable in all active EPEL10 branches. For EPEL9, python-ujson is at 5.8.0 due to breaking changes in 5.9.0, https://src.fedoraproject.org/rpms/python-ujson/pull-request/13. There are probably also some dependency issues involved in updating to the latest release, but it doesn’t matter, because I don’t think this CVE merits asking for an Updates Policy exception. However, the commit that fixed the problem, https://github.com/ultrajson/ultrajson/commit/82af1d0ac01d09aa40c887b460d44b9d9f4bccd9, is straightforward and self-contained enough that it can be backported to 5.8.0 for EPEL9.
FEDORA-EPEL-2026-204e38b37f (python-ujson-5.8.0-5.el9) has been submitted as an update to Fedora EPEL 9. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-204e38b37f
FEDORA-EPEL-2026-204e38b37f has been pushed to the Fedora EPEL 9 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-204e38b37f See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-EPEL-2026-204e38b37f (python-ujson-5.8.0-5.el9) has been pushed to the Fedora EPEL 9 stable repository. If problem still persists, please make note of it in this bug report.