PatchSiren

ohler55 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW ohler55 CVE published 2026-06-19

CVE-2026-54897

A use-after-free vulnerability exists in the Oj::Doc iterators (each_value, each_child, each_leaf) due to a reentrant close issue. When a Ruby block yielded during iteration calls doc.close or d.close, the document's heap memory is freed while the C iterator is still running, leading to a use-after-free accessible from pure Ruby. This vulnerability can lead to potential arbitrary code execution or denial [truncated]

MEDIUM ohler55 CVE published 2026-06-19

CVE-2026-54899

CVE-2026-54899 debrief: Use-After-Free in Oj::Parser Symbol Key Cache Toggle. Disabling `symbol_keys` on a reused `Oj::Parser` instance triggers a heap use-after-free. When `symbol_keys` is toggled from `true` to `false`, `opt_symbol_keys_set` frees the internal key cache (`cache_free`) but does not clear the pointer. The next `parse` call reads from the freed cache via `cache_intern`, producing a use-after-free.