Loading...
Skip to main content
RubyGems (Ruby)

oj Security Analysis

oj has 11 known security vulnerabilities in RubyGems (Ruby). Upgrade to version 3.17.3 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

11 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 3.17.3

Upgrading to 3.17.3 or later resolves all 11 known vulnerabilities in oj. Run: gem install oj -v 3.17.3

Is oj in your project?

Check if you're affected and upgrade to 3.17.3 to stay secure.

11
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

11 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-54903
Oj: Integer Overflow in Oj.load 2GB String Handling
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54902
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54901
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54900
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54898
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54897
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54896
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54592
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54502
Oj: Stack Buffer Overflow in Oj.dump via Large Indent
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54899
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
HIGH
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3
CVE-2026-54500
Oj: intern.c form_attr (uninitialized stack read)
MEDIUM
0.5, 0.5.1, 0.5.2, 0.6.0 (+290 more)3.17.3

About This Data

Vulnerability data for oj is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related RubyGems (Ruby) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of oj.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed