Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54696

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.

EPSS

Процентиль: 22%
0.00301
Низкий

3.7 Low

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.

CVSS3: 3.7
debian
около 1 месяца назад

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2. ...

EPSS

Процентиль: 22%
0.00301
Низкий

3.7 Low

CVSS3

Дефекты

CWE-122