Executive brief
Oj is a high-performance JSON processing library for the Ruby programming language. A technical flaw in how the library handles data during parsing could allow a specially crafted script to cause the application to crash or behave unpredictably. This occurs when the data being processed is modified while the library is still reading it, potentially impacting the stability of services that rely on this library for data interchange.
Technical details
A heap use-after-free vulnerability exists in Oj::Parser#parse within ext/oj/parser.c. The C engine maintains a raw 'const byte *' pointer to the internal buffer of a Ruby string. If a SAJ/SAJ2 callback (such as hash_start) mutates the input string using methods like String#replace, Ruby may reallocate the string buffer and free the original memory. The C parser continues to use the now-dangling pointer, leading to a use-after-free condition during subsequent character reads. This issue affects versions prior to 3.17.2 and requires the attacker to be able to provide a callback that mutates the input JSON string during parsing.
Affected products
- ohler55 oj < 3.17.2
Timeline
- 2026-06-16: advisory: GitHub security advisory published by maintainer
- 2026-06-30: disclosed: CVE published to NVD dataset
- 2026-07-01: patched: Fix confirmed in version 3.17.2