Executive brief
Oj is a high-performance JSON processing library for the Ruby programming language. A flaw in how it handles specific large data keys can cause the application to crash or experience memory corruption when processing specially crafted JSON input. This could lead to service interruptions (Denial of Service) for applications that use this library to parse untrusted data from the internet.
Technical details
A vulnerability exists in the `Oj::Parser#parse` method when running in 'usual' mode with `create_id` enabled. In `ext/oj/usual.c`, the `form_attr` function performs an integer cast on the key length (`slen`). When a key is exactly 65,535 bytes, the calculation `(int)slen + 1` results in an integer overflow or truncation that leads to a `memcpy` call with a size interpreted as `SIZE_MAX`. This results in an out-of-bounds write/heap corruption and an immediate process crash. The issue is reachable via the network if the application parses user-supplied JSON. It has been patched in version 3.17.2.
Affected products
- ohler55 oj < 3.17.2
Timeline
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date
- 2026-07-01: other: Advisory record updated