VulnSea

oj vulnerabilities

CVEs whose affected-version data names the oj package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-54899High
3mo ago

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54502High
3mo ago

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

Twilightoj · ojEPSS 0.34%via GHSA
CVE-2026-54500Medium· 5.3
3mo ago

Oj: intern.c form_attr (uninitialized stack read)

Oj: intern.c form_attr (uninitialized stack read)

Sunlitoj · ojEPSS 0.20%via GHSA
CVE-2026-54592High· 7.5
3mo ago

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Twilightoj · ojEPSS 0.28%via GHSA
CVE-2026-54896High
3mo ago

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54897High
3mo ago

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54898High
3mo ago

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54900HighPoC
3mo ago

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Midnightoj · ojEPSS 0.43%via GHSA
CVE-2026-54901High
3mo ago

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54902High
3mo ago

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54903High
3mo ago

Oj: Integer Overflow in Oj.load 2GB String Handling

Oj: Integer Overflow in Oj.load 2GB String Handling

Twilightoj · ojEPSS 0.43%via GHSA
oj vulnerabilities (CVEs) · VulnSea