Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
Published Jun 30, 2026
8.7
HIGHCVSS 4.0
EPSS 0.15%
Description
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in object mode, Oj.dump is vulnerable to a heap buffer overflow when serializing Exception objects with a large :indent value. The serializer allocates a buffer sized for the object's attributes but does not account for the indent bytes added on each write. With indent: 5000, the accumulation of 5,000-byte indent strings overflows the 13,150-byte heap allocation, corrupting adjacent heap memory. This issue has been fixed in version 3.17.2.
Affected products
-
- Version < 3.17.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat's only product shipping the Oj Ruby gem (Compliance Backend) already includes version 3.17.3, which contains the fix for this vulnerability. No Red Hat products are affected.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-54896 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2495716 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40852 Advisory
- https://github.com/advisories/GHSA-35w3-pjm6-wj95 Advisory
- https://github.com/ohler55/oj/security/advisories/GHSA-35w3-pjm6-wj95 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-54896
- https://www.cve.org/CVERecord?id=CVE-2026-54896
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54896 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2495716 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40852 | Advisory | |
| https://github.com/advisories/GHSA-35w3-pjm6-wj95 | Advisory | |
| https://github.com/ohler55/oj/security/advisories/GHSA-35w3-pjm6-wj95 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54896 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54896 |
Change history (0)
No recorded changes yet.