PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54897 ohler55 CVE debrief

A use-after-free vulnerability exists in the Oj::Doc iterators (each_value, each_child, each_leaf) due to a reentrant close issue. When a Ruby block yielded during iteration calls doc.close or d.close, the document's heap memory is freed while the C iterator is still running, leading to a use-after-free accessible from pure Ruby. This vulnerability can lead to potential arbitrary code execution or denial of service. Defenders should prioritize verifying the presence of the vulnerability in their inventory and assessing the exposure of their systems, especially those using the affected versions of the oj gem. The issue is fixed in version 3.17.3 or later.

Vendor
ohler55
Product
oj
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-10-06
Advisory published
2026-06-19
Advisory updated
2026-10-06

Who should care

Defenders responsible for RubyGems inventory management and oj gem usage should assess exposure and prioritize verification and remediation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams who use the affected versions of the oj gem. They should verify the presence of this vulnerability in their inventory and assess the exposure of their systems.

Why it matters

The use-after-free vulnerability in Oj::Doc iterators poses a risk to systems using the affected versions of the oj gem, requiring defenders to verify exposure and prioritize remediation efforts.

  • Potential for arbitrary code execution or denial of service due to use-after-free vulnerability
  • Need for verification of affected versions in inventory
  • Priority for updating to fixed version 3.17.3 or later

Technical summary

The Oj::Doc iterators (each_value, each_child, each_leaf) are vulnerable to a heap use-after-free. When a Ruby block yielded during iteration calls doc.close or d.close, the document's heap memory is freed while the C iterator is still running. When control returns from the block, the iterator reads from the freed region, producing a use-after-free accessible from pure Ruby. This vulnerability can lead to potential arbitrary code execution or denial of service. The issue is fixed in version 3.17.3 or later. Defenders should prioritize verifying the presence of the vulnerability in their inventory and assessing the exposure of their systems.

Defensive priority

Defenders should prioritize verifying the presence of the vulnerability in their inventory and assessing the exposure of their systems, especially those using the affected versions of the oj gem.

Recommended defensive actions

  • Verify the presence of the vulnerability in your inventory
  • Assess the exposure of your systems, especially those using the affected versions of the oj gem
  • Update to version 3.17.3 or later if possible
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is confirmed to exist in all versions of the oj gem with ext/oj/fast.c, including version 3.17.1. The issue is fixed in version 3.17.3. Defenders should verify the presence of this vulnerability in their inventory and assess the exposure of their systems. The CVE record was published on 2026-06-19T19:36:50.000Z and has not been modified since then. The vulnerability poses a risk to systems using the affected versions of the oj gem.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54897 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54897

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54897 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54897

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/RubyGems/GHSA-9ppp-w3g4-fh4q.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ohler55/oj/security/advisories/GHSA-9ppp-w3g4-fh4q

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ohler55/oj

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/oj/CVE-2026-54897.yml

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.