oj vulnerabilities
CVEs whose affected-version data names the oj package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-54502HighOj: Stack Buffer Overflow in Oj.dump via Large Indent
Oj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-54500Medium· 5.3Oj: intern.c form_attr (uninitialized stack read)
Oj: intern.c form_attr (uninitialized stack read)
CVE-2026-54592High· 7.5Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2026-54896HighOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
CVE-2026-54897HighOj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
CVE-2026-54898HighOj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
CVE-2026-54900HighPoCOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-54901HighOj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-54902HighOj: Use-After-Free in Oj::Parser SAJ Long Key Callback
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-54903HighOj: Integer Overflow in Oj.load 2GB String Handling
Oj: Integer Overflow in Oj.load 2GB String Handling