Skip to content

v2.5.4: Fix msgpack CVE-2026-57585 and ujson crashes

Latest

Choose a tag to compare

@github-actions github-actions released this 27 Sep 19:08
· 7 commits to master since this release
fe0b803

Security fix for the vendored msgpack, plus fixes for crashes in the vendored ujson.

Security

  • Fix CVE-2026-57585 (GHSA-6v7p-g79w-8964) in the vendored msgpack: reusing an srsly.msgpack.Unpacker after a failed unpack could crash the process. Backports the upstream msgpack-python fix. The high-level helpers such as srsly.msgpack_loads create a new unpacker for each call, so they were not exposed. (#124, #127)

Bug fixes

  • Fix a segfault on Python 3.14 when calling srsly.ujson.dumps(..., sort_keys=True) on a dict. (#128)
  • Fix a segfault on all Python versions when srsly.ujson.dumps(..., sort_keys=True) is given keys that can't be sorted, such as {1: 1, "a": 2}. It now raises TypeError, like the standard library json module. (#128)
  • Fix a memory leak in srsly.ujson when encoding a large object fails partway through. (#128)

srsly.json_dumps was not affected by the sort_keys crashes, because it uses the standard library json module when sort_keys=True.

Maintenance

  • Test on Python 3.13 and 3.14 in CI. (#128)
  • Update the vendored cloudpickle tests to match the vendored cloudpickle 3.1.2. (#121, #126)
  • Remove the publish_pypi workflow from this repository. (#129)