PatchSiren cyber security CVE debrief
CVE-2026-54897 ohler55 CVE debrief
A use-after-free vulnerability exists in the Oj::Doc iterators (each_value, each_child, each_leaf) due to a reentrant close issue. When a Ruby block yielded during iteration calls doc.close or d.close, the document's heap memory is freed while the C iterator is still running, leading to a use-after-free accessible from pure Ruby. This vulnerability can lead to potential arbitrary code execution or denial of service. Defenders should prioritize verifying the presence of the vulnerability in their inventory and assessing the exposure of their systems, especially those using the affected versions of the oj gem. The issue is fixed in version 3.17.3 or later.
- Vendor
- ohler55
- Product
- oj
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-10-06
Who should care
Defenders responsible for RubyGems inventory management and oj gem usage should assess exposure and prioritize verification and remediation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams who use the affected versions of the oj gem. They should verify the presence of this vulnerability in their inventory and assess the exposure of their systems.
Why it matters
The use-after-free vulnerability in Oj::Doc iterators poses a risk to systems using the affected versions of the oj gem, requiring defenders to verify exposure and prioritize remediation efforts.
- Potential for arbitrary code execution or denial of service due to use-after-free vulnerability
- Need for verification of affected versions in inventory
- Priority for updating to fixed version 3.17.3 or later
Technical summary
The Oj::Doc iterators (each_value, each_child, each_leaf) are vulnerable to a heap use-after-free. When a Ruby block yielded during iteration calls doc.close or d.close, the document's heap memory is freed while the C iterator is still running. When control returns from the block, the iterator reads from the freed region, producing a use-after-free accessible from pure Ruby. This vulnerability can lead to potential arbitrary code execution or denial of service. The issue is fixed in version 3.17.3 or later. Defenders should prioritize verifying the presence of the vulnerability in their inventory and assessing the exposure of their systems.
Defensive priority
Defenders should prioritize verifying the presence of the vulnerability in their inventory and assessing the exposure of their systems, especially those using the affected versions of the oj gem.
Recommended defensive actions
- Verify the presence of the vulnerability in your inventory
- Assess the exposure of your systems, especially those using the affected versions of the oj gem
- Update to version 3.17.3 or later if possible
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is confirmed to exist in all versions of the oj gem with ext/oj/fast.c, including version 3.17.1. The issue is fixed in version 3.17.3. Defenders should verify the presence of this vulnerability in their inventory and assess the exposure of their systems. The CVE record was published on 2026-06-19T19:36:50.000Z and has not been modified since then. The vulnerability poses a risk to systems using the affected versions of the oj gem.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54897 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54897
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54897 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54897
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/RubyGems/GHSA-9ppp-w3g4-fh4q.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/ohler55/oj/security/advisories/GHSA-9ppp-w3g4-fh4q
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/ohler55/oj
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/oj/CVE-2026-54897.yml
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.