oj has 11 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 11 in the 90 before. The busiest recent month was June 2026 with 11. The median CVSS is 6.4 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-416 (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 11
Worst active — by depth score
CVE-2026-54900HighOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling53CVE-2026-54903HighOj: Integer Overflow in Oj.load 2GB String Handling41CVE-2026-54902HighOj: Use-After-Free in Oj::Parser SAJ Long Key Callback41CVE-2026-54901HighOj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking41CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle41
oj vulnerabilities
CVEs affecting oj, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-54502HighOj: Stack Buffer Overflow in Oj.dump via Large Indent
Oj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-54500Medium· 5.3Oj: intern.c form_attr (uninitialized stack read)
Oj: intern.c form_attr (uninitialized stack read)
CVE-2026-54592High· 7.5Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2026-54896HighOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
CVE-2026-54897HighOj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
CVE-2026-54898HighOj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
CVE-2026-54900HighPoCOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-54901HighOj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-54902HighOj: Use-After-Free in Oj::Parser SAJ Long Key Callback
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-54903HighOj: Integer Overflow in Oj.load 2GB String Handling
Oj: Integer Overflow in Oj.load 2GB String Handling