Description
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mark array_class and hash_class references during garbage collection, leading to Use-After-Free. If GC runs after the class is assigned but before a parse, the class object is reclaimed, leaving the parser holding a dangling VALUE. The subsequent parse call dereferences the freed object, producing a segfault. This issue has been fixed in version 3.17.2.
Published: 2026-06-30
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oj (Optimized JSON) is a Ruby gem that parses JSON and performs object marshalling. In any version prior to 3.17.2, Oj::Parser in the usual mode fails to mark array_class and hash_class references during garbage collection after assigning the class but before a subsequent parse; when the object is reclaimed, the parser holds a dangling pointer. The resulting segmentation fault terminates the application, representing a classic use‑after‑free flaw identified as CWE‑416.

Affected Systems

The affected product is the Ruby gem oj, provided by ohler55, version 3.17.1 and earlier; any Ruby application that requires this gem and invokes Oj::Parser in the default mode—such as web frameworks, background workers, or command‑line tools—may be affected.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity; EPSS data is unavailable, and it is not listed in CISA KEV catalog. The described use‑after‑free occurs when a garbage collection is triggered between class assignment and the subsequent parse; the attacker would need to control or induce a GC cycle that frees the class reference before the parser is invoked with untrusted JSON. Successful exploitation leads to application termination but provides no code execution or data disclosure. Based on the description, the likely attack vector is an attacker supplying malicious JSON that triggers the parser after a garbage collection cycle has reclaimed the class reference. This inference is not directly stated in the CVE text.

Generated by OpenCVE AI on July 1, 2026 at 15:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the oj gem to version 3.17.2 or newer, which implements proper garbage‑collection marking for array_class and hash_class.
  • If an immediate upgrade is not feasible, isolate any usage of oj so that untrusted JSON data cannot reach the parser until the patch is applied.
  • Monitor application logs for segmentation faults or crashes that may indicate exploitation of the use‑after‑free flaw.

Generated by OpenCVE AI on July 1, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vwm4-62gf-x745 Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
History

Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Ohler
Ohler oj
Vendors & Products Ohler
Ohler oj

Wed, 01 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mark array_class and hash_class references during garbage collection, leading to Use-After-Free. If GC runs after the class is assigned but before a parse, the class object is reclaimed, leaving the parser holding a dangling VALUE. The subsequent parse call dereferences the freed object, producing a segfault. This issue has been fixed in version 3.17.2.
Title Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Weaknesses CWE-416
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-01T12:34:23.576Z

Reserved: 2026-06-16T13:49:33.555Z

Link: CVE-2026-54901

cve-icon Vulnrichment

Updated: 2026-07-01T12:34:09.073Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-30T23:36:38Z

Links: CVE-2026-54901 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T15:15:04Z

Weaknesses