
CVE-2026-54899 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling symbol_keys on a reused Oj::Parser instance trig… https://www.cve.org/CVERecord?id=CVE-2026-54899
Post summary
The CVE-2026-54899 flaw in the Oj Ruby gem affects instances prior to version 3.17.2 and can be mitigated by upgrading to that or later releases; no exploitation evidence or PoC is provided.


