Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-54502

CVE-2026-54502: Oj Ruby Gem Buffer Overflow Vulnerability

CVE-2026-54502 is a stack-based buffer overflow vulnerability in the Oj Ruby gem that occurs when a large indent value is provided. This article covers the technical details, affected versions, and mitigation steps.

Published:

CVE-2026-54502 Overview

CVE-2026-54502 is a stack-based buffer overflow [CWE-121] in Oj (Optimized JSON), a JSON parser and Object marshaller distributed as a Ruby gem. The flaw affects Oj versions prior to 3.17.2. When a developer passes an excessively large :indent value to Oj.dump, the fill_indent routine in dump.h invokes memset without validating the size argument. Passing INT_MAX causes memset to write approximately 2 GB into a stack-allocated buffer of 4,184 bytes, corrupting the stack and crashing the Ruby process. The maintainers fixed the issue in version 3.17.2.

Critical Impact

Applications using vulnerable Oj versions with attacker-influenced :indent parameters can be forced into a denial-of-service condition through stack corruption.

Affected Products

  • Oj (Optimized JSON) Ruby gem versions prior to 3.17.2
  • Ruby applications that expose the :indent option of Oj.dump to untrusted input
  • Downstream Ruby projects and services bundling vulnerable Oj releases

Discovery Timeline

  • 2026-07-01 - CVE-2026-54502 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-54502

Vulnerability Analysis

The vulnerability resides in the fill_indent function defined in dump.h. This helper prepares an indentation string used by Oj.dump when serializing Ruby objects to JSON. The function calls memset(indent_str, ' ', (size_t)opts->indent) directly, using the developer-supplied opts->indent value as the length argument.

The indent_str buffer is allocated on the stack as part of the out structure, sized at 4,184 bytes. Because memset receives no bounds check, writing anything larger than the buffer overruns the stack frame. Supplying INT_MAX (2,147,483,647) forces the function to write roughly 2 GB of space characters onto the stack, immediately corrupting saved return addresses, frame pointers, and adjacent locals.

The practical outcome is a process crash and denial of service. Because the overflow is triggered through a Ruby-level API rather than direct memory manipulation, exploitation for code execution is unlikely, but availability impact is reliable. The EPSS score for this issue is 0.257%.

Root Cause

The root cause is missing input validation on the :indent option. The (size_t) cast in fill_indent preserves the full 32-bit signed integer value when converted, so no truncation limits the write. Oj never compares opts->indent against the size of the destination buffer before invoking memset.

Attack Vector

Exploitation requires that an application pass attacker-controlled or unvalidated data into the :indent option of Oj.dump. Any Ruby service that accepts formatting parameters from HTTP requests, configuration files, or message queues and forwards them to Oj is exposed. A single serialization call with indent: 2147483647 is sufficient to crash the worker process.

Refer to the GitHub Security Advisory GHSA-3v45-f3vh-wg7m for the upstream technical description.

Detection Methods for CVE-2026-54502

Indicators of Compromise

  • Unexpected SIGSEGV or SIGABRT crashes in Ruby processes that call Oj.dump
  • Core dumps showing large contiguous regions of 0x20 (space) bytes on the stack
  • Application logs recording repeated worker restarts after JSON serialization calls
  • HTTP requests or job payloads containing extremely large numeric indent values

Detection Strategies

  • Inventory Ruby projects and Gemfile.lock files for Oj versions below 3.17.2
  • Audit source code for calls to Oj.dump where the :indent option is populated from external input
  • Enable process crash monitoring on Ruby application servers to surface serialization-induced faults
  • Instrument web application firewalls or API gateways to flag oversized numeric parameters in JSON formatting fields

Monitoring Recommendations

  • Forward Ruby application crash telemetry and syslog signal events to a centralized log platform for correlation
  • Track deployment manifests for gems below patched versions using software composition analysis tools
  • Alert on abnormal spikes in memory allocation preceding worker termination in Puma, Unicorn, or Sidekiq processes

How to Mitigate CVE-2026-54502

Immediate Actions Required

  • Upgrade the Oj gem to version 3.17.2 or later in all Ruby applications
  • Rebuild and redeploy container images that bundle vulnerable Oj releases
  • Reject or clamp externally supplied :indent values before passing them to Oj.dump

Patch Information

The maintainers released Oj 3.17.2 with a size validation applied before the memset call in fill_indent. Update Gemfile entries to require >= 3.17.2, then run bundle update oj and redeploy. See the GitHub Security Advisory GHSA-3v45-f3vh-wg7m for maintainer guidance.

Workarounds

  • Validate that any user-influenced :indent value falls within a small, reasonable range such as 0 to 16
  • Remove the :indent option entirely from serialization paths that do not require pretty-printed output
  • Isolate Ruby workers that process untrusted JSON serialization requests so crashes do not affect other services
bash
# Configuration example
bundle update oj --conservative
bundle list | grep oj  # verify oj (>= 3.17.2)

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.