HIGH 7.5 RubyGems
Out-of-bounds Read in Ruby JSON Parser
GHSA-9m3q-rhmv-5q44 · CVE-2025-27788
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
A specially crafted document could cause an out of bound read, most likely resulting in a crash.
Versions 2.10.0 and 2.10.1 are impacted. Older versions are not.
Patches
Version 2.10.2 fixes the problem.
Workarounds
None.
References
- WEB https://github.com/ruby/json/security/advisories/GHSA-9m3q-rhmv-5q44
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-27788
- WEB https://github.com/ruby/json/commit/c56db31f800d5d508389793e69682f99749dbadf
- PACKAGE https://github.com/ruby/json
- WEB https://github.com/ruby/json/releases/tag/v2.10.2
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2025-27788.yml
Ready to move
Start Securing
Free, no credit card | First findings in minutes