CVE-2026-54500Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is >= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-908

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 207-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54500 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memo… https://www.cve.org/CVERecord?id=CVE-2026-54500 ----- Traducción: CVE-2026-54500 Oj … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑54500, a vulnerability in the Oj Ruby gem affecting versions before 3.17.3 where Oj.load can access uninitialized stack memo.

    0000047
    90 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54500 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memo… https://www.cve.org/CVERecord?id=CVE-2026-54500

    Post summary

    CVE-2026-54500 is a memory safety vulnerability in the Oj Ruby gem affecting versions below 3.17.3; upgrading to the latest release mitigates the issue. No PoC, exploit, or active exploitation evidence is presented.

    00000742
    57.7K followersView on X

Explore more