json vulnerabilities
CVEs whose affected-version data names the json package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-71847LowRuby JSON is a JSON implementation for Ruby
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released stora…
▾ Sunlitjson · jsonEPSS 0.39%via NVD
CVE-2026-54696Low· 3.7Ruby json: JSON generator heap buffer overflow when streaming to an IO
Ruby json: JSON generator heap buffer overflow when streaming to an IO
▾ Sunlitjson · jsonEPSS 0.38%via GHSA
CVE-2026-33210Critical· 9.1Ruby JSON is a JSON implementation for Ruby
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_d…
▾ Midnightruby-lang · jsonEPSS 0.86%via NVD