Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54696

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.

A flaw was found in Ruby JSON. A remote attacker could exploit a heap buffer overflow vulnerability by providing an oversized streamed object containing a specially crafted string. This could lead to a reliable process crash, resulting in a denial of service (DoS) for the affected system.

Отчет

This Low impact flaw in Ruby JSON can lead to a denial of service in applications that process untrusted, oversized streamed JSON objects. The vulnerability arises from a heap buffer overflow when the JSON generator attempts to write past its internal buffer with an attacker-controlled string near 16 KB, resulting in a process crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Out of support scope
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel8Out of support scope
Red Hat AMQ ClientsjsonFix deferred
Red Hat Enterprise Linux 10rubyFix deferred
Red Hat Enterprise Linux 10ruby4.0Fix deferred
Red Hat Enterprise Linux 10ubi10/ruby-33Fix deferred
Red Hat Enterprise Linux 10ubi10/ruby-40Fix deferred
Red Hat Enterprise Linux 8pcsFix deferred
Red Hat Enterprise Linux 8ruby:3.3/rubyFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2495409json: Ruby JSON: Denial of service via heap buffer overflow with oversized streamed objects

EPSS

Процентиль: 22%
0.00301
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.

CVSS3: 3.7
nvd
около 1 месяца назад

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.

CVSS3: 3.7
debian
около 1 месяца назад

Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2. ...

CVSS3: 3.7
github
12 дней назад

Ruby json: JSON generator heap buffer overflow when streaming to an IO

EPSS

Процентиль: 22%
0.00301
Низкий

3.7 Low

CVSS3