Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
Published Jun 30, 2026
8.7
HIGHCVSS 4.0
EPSS 0.15%
Description
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parser#parse is vulnerable to a heap use-after-free when a SAJ/SAJ2 callback mutates the input JSON string during parsing. The C engine holds a raw const byte * pointer into the Ruby string's internal buffer. If a callback (e.g. hash_start) resizes the string — for example by calling String#replace with a longer value — Ruby reallocates the string buffer and frees the old one. The C parser's pointer is left dangling; the next character read at parser.c:607 is a use-after-free. This issue has been fixed in version 3.17.2.
Affected products
-
- Version < 3.17.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat's only product shipping the Oj Ruby gem (Compliance Backend) already includes version 3.17.3, which contains the fix for this vulnerability. No Red Hat products are affected.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-54898 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2495699 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40854 Advisory
- https://github.com/advisories/GHSA-q2gm-54r6-8fwm Advisory
- https://github.com/ohler55/oj/security/advisories/GHSA-q2gm-54r6-8fwm exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-54898
- https://www.cve.org/CVERecord?id=CVE-2026-54898
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54898 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2495699 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40854 | Advisory | |
| https://github.com/advisories/GHSA-q2gm-54r6-8fwm | Advisory | |
| https://github.com/ohler55/oj/security/advisories/GHSA-q2gm-54r6-8fwm | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54898 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54898 |
Change history (0)
No recorded changes yet.