Intel

AIKIDO-2026-729119

oj is vulnerable to Out-of-bounds Write

Out-of-bounds Write Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 5 days ago

59

Medium Risk

This Affects:

RUBYoj
1.3.7 - 3.17.3
Fixed in 3.17.4
Are you affected? Scan for Free

TL;DR

oj parses and dumps JSON with fixed size C buffers. A ^u Struct with too many member names, a deep array dumped with an integer indent, or a read that returns too many bytes writes past those buffers and corrupts stack or heap memory. A comment that runs to the end of the document reads past the buffer, and Oj::Doc on a document with no root uses a null pointer, so the process crashes. The fix stops at the end of each buffer and returns an error when the Struct class or document root is missing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use oj to parse untrusted data.

Background info

oj is vulnerable to Out-of-bounds Write in versions 1.3.7 - 3.17.3.

How to fix this

Upgrade the oj library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform