11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether oj is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-54898
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
UNKNOWN
CVE-2026-54902
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
UNKNOWN
CVE-2026-54897
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
UNKNOWN
CVE-2026-54903
Oj: Integer Overflow in Oj.load 2GB String Handling
UNKNOWN
CVE-2026-54896
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
UNKNOWN
CVE-2026-54899
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
HIGH 7.5
CVE-2026-54592
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
UNKNOWN
CVE-2026-54502
Oj: Stack Buffer Overflow in Oj.dump via Large Indent
MEDIUM 5.3
CVE-2026-54500
Oj: intern.c form_attr (uninitialized stack read)
UNKNOWN
CVE-2026-54900
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
UNKNOWN
CVE-2026-54901
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes