Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:gem/oj

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.

Join the discussion
0

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerable to Use-After-Free when in SAJ mode. The Oj::Parser does not protect cached object keys (≥ 35 bytes) from garbage collection, and a Ruby callback that triggers GC inside hash_end can cause the key string to be reclaimed while the C parser still holds a pointer to it. The subsequent access to the freed string VALUE results in a segfault, confirmed by an RIP pointing to address 0x4242 (a canary-style pattern suggesting control over the freed memory's content). This issue has been fixed in version 3.17.2.

Join the discussion
0

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mark array_class and hash_class references during garbage collection, leading to Use-After-Free. If GC runs after the class is assigned but before a parse, the class object is reclaimed, leaving the parser holding a dangling VALUE. The subsequent parse call dereferences the freed object, producing a segfault. This issue has been fixed in version 3.17.2.

Join the discussion

Oj (Optimized JSON) is a Ruby gem for JSON parsing and object marshalling. Versions prior to 3.17.2 contain an integer overflow vulnerability in the usual mode with create_id enabled. Specifically, when a JSON object key is exactly 65,535 bytes long, an integer truncation causes a negative size to be passed to memcpy, resulting in heap corruption and process crash. This issue is fixed in version 3.17.2.

Join the discussion
0

Oj (Optimized JSON) is a Ruby gem for JSON parsing and object marshalling. Versions prior to 3.17.2 contain a use-after-free vulnerability in the Oj::Parser#parse method when a SAJ/SAJ2 callback mutates the input JSON string during parsing. This occurs because the C parser holds a raw pointer to the Ruby string's internal buffer, which can be reallocated and freed if the string is resized during a callback. The issue has been fixed in version 3.17.2.

Join the discussion
0

Oj (Optimized JSON) is a Ruby gem for JSON parsing and object marshalling. Versions prior to 3.17.2 have a heap use-after-free vulnerability in Oj::Doc iterators (each_value, each_child, each_leaf). This occurs when a Ruby block yields during iteration and calls doc.close or d.close, freeing the document's heap memory while the C iterator is still active. The iterator then accesses freed memory, causing a use-after-free condition. This vulnerability has been fixed in version 3.17.2.

Join the discussion

Oj (Optimized JSON) is a Ruby gem for JSON parsing and object marshalling. Versions prior to 3.17.2 have a heap-based buffer overflow vulnerability in Oj.dump when serializing Exception objects with a large indent value in object mode. The overflow occurs because the serializer does not account for the added indent bytes, leading to heap memory corruption. This issue is fixed in version 3.17.2.

Join the discussion

Oj (Optimized JSON) is a Ruby gem JSON parser vulnerable to an out-of-bounds read in versions prior to 3.17.3. The vulnerability occurs in the Oj::Doc#each_child method when recursively processing deeply nested JSON documents, causing a fixed-size stack buffer overflow and process abort (DoS). This is due to missing bounds checks and improper stack pointer restoration during recursion. The issue has been fixed in version 3.17.3.

Join the discussion

Oj (Optimized JSON) is a Ruby gem for JSON parsing and marshalling. Versions prior to 3.17.2 contain a stack-based buffer overflow vulnerability in the Oj.dump function when a large :indent value is used. The vulnerability arises because the fill_indent function calls memset with the indent size unchecked, allowing an attacker to cause a stack overflow by specifying a very large indent value such as INT_MAX. This issue has been fixed in version 3.17.2.

Join the discussion

Oj (Optimized JSON) is a Ruby gem for JSON parsing and object marshalling. Versions prior to 3.17.3 contain an out-of-bounds read vulnerability in the Oj.load function when parsing JSON objects with keys 254 bytes or longer. This flaw causes uninitialized stack memory to be read and potentially disclosed to the caller via interned symbols or error messages. The issue has been fixed in version 3.17.3.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Package: pkg:gem/oj
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses