·
7 commits
to master
since this release
Security fix for the vendored msgpack, plus fixes for crashes in the vendored ujson.
Security
- Fix CVE-2026-57585 (GHSA-6v7p-g79w-8964) in the vendored msgpack: reusing an
srsly.msgpack.Unpackerafter a failed unpack could crash the process. Backports the upstream msgpack-python fix. The high-level helpers such assrsly.msgpack_loadscreate a new unpacker for each call, so they were not exposed. (#124, #127)
Bug fixes
- Fix a segfault on Python 3.14 when calling
srsly.ujson.dumps(..., sort_keys=True)on a dict. (#128) - Fix a segfault on all Python versions when
srsly.ujson.dumps(..., sort_keys=True)is given keys that can't be sorted, such as{1: 1, "a": 2}. It now raisesTypeError, like the standard libraryjsonmodule. (#128) - Fix a memory leak in
srsly.ujsonwhen encoding a large object fails partway through. (#128)
srsly.json_dumps was not affected by the sort_keys crashes, because it uses the standard library json module when sort_keys=True.