Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer. fill_indent in dump.h calls memset(indent_str, ' ', (size_t)opts->indent) without validating the size. When opts->indent is set to INT_MAX (2,147,483,647), the (size_t) cast preserves the large value and memset writes 2 GB into the stack-allocated out buffer (4,184 bytes), corrupting the stack and crashing the process. This issue has been fixed in version 3.17.2.
CVSS
No CVSS.
References
Configurations
No configuration.
History
01 Jul 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-01 00:16
Updated : 2026-07-01 00:16
NVD link : CVE-2026-54502
Mitre link : CVE-2026-54502
CVE.ORG link : CVE-2026-54502
JSON object : View
Products Affected
No product.
CWE
CWE-121
Stack-based Buffer Overflow
