6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether json is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
LOW 3.7
CVE-2026-54696
Ruby json: JSON generator heap buffer overflow when streaming to an IO
UNKNOWN
CVE-2026-33210
Ruby JSON has a format string injection vulnerability
HIGH 7.5
CVE-2025-27788
Out-of-bounds Read in Ruby JSON Parser
UNKNOWN
CVE-2013-0269
JSON gem has Improper Input Validation vulnerability
HIGH 7.5
CVE-2020-10663
Unsafe object creation in json RubyGem
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes