CVE-2026-54592High· 7.5▾ TwilightOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.3%
Oj::Doc#each_child, when invoked recursively over a deeply nested JSON
document, overflows a fixed-size stack buffer and aborts the process. This is a
denial of service reachable from untrusted JSON.
Two-step chain in ext/oj/fast.c:
doc_each_child (~line 1501) increments doc->where past the
where_path[MAX_STACK = 100] array with no bounds check, and never restores
it (doc->where-- is missing). Calling each_child recursively from inside
the yield block therefore drives doc->where beyond the array.
On the next entry (~line 1478) the function copies the path into a stack-local buffer:
Leaf save_path[MAX_STACK]; // 800-byte stack buffer
size_t wlen = doc->where - doc->where_path;
if (0 < wlen) {
memcpy(save_path, doc->where_path, sizeof(Leaf) * (wlen + 1));
}
When the previous recursive call left doc->where past where_path[100],
wlen exceeds MAX_STACK and the memcpy overflows save_path on the C
stack.
The Oj::Doc parser imposes no JSON nesting-depth limit (it relies on a
C-stack pressure check), so deeply nested attacker input reaches this path.
require 'oj'
depth = 200
payload = '[' * depth + '1' + ']' * depth
Oj::Doc.open(payload) do |doc|
r = lambda { doc.each_child { |_| r.call } }
r.call
end
Recursion depth <= 99 iterates normally; depth >= 101 aborts. lldb backtrace
on the affected build (ruby 3.3.8 / arm64-darwin24):
SIGABRT
#2 __abort
#3 __stack_chk_fail
#4 doc_each_child (oj.bundle, fast.c)
Reliable denial of service: any endpoint that calls
Oj::Doc.open(untrusted) { |d| d.each_child ... } recursively can be crashed
with a small deeply-nested payload. On builds with a stack protector (the
default, -fstack-protector-strong) the canary aborts the process before the
saved return address is used. The Step-1 heap OOB writes into struct _doc
fields do occur, but are masked in practice because the Step-2 stack overflow
crashes first; turning them into anything beyond a crash has not been
demonstrated.
Fixed in 3.17.3: doc_each_child now bounds-checks before incrementing
doc->where (raising Oj::DepthError) and restores doc->where after the
loop, matching the existing each_leaf pattern. Verified on the fixed build:
depth >= 101 raises a clean Oj::DepthError instead of aborting.
Reported by Zac Wang (@7a6163).
oj < 3.17.3Upgrade to a patched release:
oj 3.17.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54500Medium· 5.3Oj: intern.c form_attr (uninitialized stack read)
CVE-2021-4034High· 7.8A local privilege escalation vulnerability was found on polkit's pkexec utility
CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-54502HighOj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-54896HighOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
CVE-2026-54897HighOj: Use-After-Free in Oj::Doc Iterators via Reentrant Close