CVE-2026-54696

NameCVE-2026-54696
DescriptionRuby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ruby-json (PTS)bullseye2.3.0+dfsg-1fixed
bookworm2.6.3+dfsg-1fixed
trixie2.9.1+dfsg-1vulnerable
forky, sid2.21.1+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ruby-jsonsourcebullseye(not affected)
ruby-jsonsourcebookworm(not affected)
ruby-jsonsource(unstable)2.19.9+dfsg-1

Notes

[trixie] - ruby-json <no-dsa> (Minor issue)
[bookworm] - ruby-json <not-affected> (Vulnerable code introduced in 2.9.0)
[bullseye] - ruby-json <not-affected> (Vulnerable code introduced in 2.9.0)
https://github.com/ruby/json/security/advisories/GHSA-x2f5-4prf-w687
Fixed by: https://github.com/ruby/json/commit/fd6a65bd08e5f3a429c03919ebfd8dd19158f095 (v2.19.9)

Search for package or bug name: Reporting problems