GEM · AUGUST 2026 · CONFIRMED

Ruby JSON Gem Vulnerability: Critical Heap-Use-After-Free Issue

Severity
HIGH
Affected component
json (gem)
Affected versions
>= 2.18.0, < 2.19.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.16.0, < 2.17.1.2 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.14.0, < 2.15.2.1 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.20.0, < 2.21.2 or >= 2.20.0, <= 2.20.0 or >= 2.21.0, <= 2.21.0 or >= 2.21.1, <= 2.21.1 or >= 2.10.0, < 2.10.2 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or < 2.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.5.5, <= 1.5.5 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.6.8, <= 1.6.8 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6 or >= 1.7.7, <= 1.7.7 or >= 1.8.0, <= 1.8.0 or >= 1.8.1, <= 1.8.1 or >= 1.8.2, <= 1.8.2 or >= 1.8.3, <= 1.8.3 or >= 1.8.5, <= 1.8.5 or >= 1.8.6, <= 1.8.6 or >= 2.0.0, <= 2.0.0 or >= 2.0.1, <= 2.0.1 or >= 2.0.2, <= 2.0.2 or >= 2.0.3, <= 2.0.3 or >= 2.0.4, <= 2.0.4 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.9.0, < 2.19.9 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or >= 2.10.2, <= 2.10.2 or >= 2.11.0, <= 2.11.0 or >= 2.11.1, <= 2.11.1 or >= 2.11.2, <= 2.11.2 or >= 2.11.3, <= 2.11.3 or >= 2.12.0, <= 2.12.0 or >= 2.12.1, <= 2.12.1 or >= 2.12.2, <= 2.12.2 or >= 2.13.0, <= 2.13.0 or >= 2.13.1, <= 2.13.1 or >= 2.13.2, <= 2.13.2 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.15.2.1, <= 2.15.2.1 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.17.1.2, <= 2.17.1.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.19.2, <= 2.19.2 or >= 2.19.3, <= 2.19.3 or >= 2.19.4, <= 2.19.4 or >= 2.19.5, <= 2.19.5 or >= 2.19.6, <= 2.19.6 or >= 2.19.7, <= 2.19.7 or >= 2.19.8, <= 2.19.8 or >= 2.9.0, <= 2.9.0 or >= 2.9.1, <= 2.9.1 or < 1.5.5 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, < 1.6.8 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.7.0, < 1.7.7 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6
Patched version
Not yet available
GHSA-9HJ4-R449-HFVC

A confirmed critical vulnerability in Ruby's JSON gem could lead to a heap-use-after-free condition and potential process termination. Users of affected versions should take immediate action.

What happened

The vulnerability, tracked as GHSA-9HJ4-R449-HFVC, arises from the JSON native C extension improperly handling consumed input buffers. This results in state pointers referencing released storage, leading to a heap-use-after-free condition. The issue has been confirmed by multiple independent sources and is rated as HIGH severity.

The vulnerability affects a wide range of versions of the json gem, including but not limited to versions >= 2.18.0, < 2.19.2 and >= 2.16.0, < 2.17.1.2. The specific versions impacted are detailed in the affected components section. No exploitation in the wild has been reported at this time.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If json is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using any version of the json gem within the specified vulnerable ranges, as detailed in the affected components section.

What should I do right now?

Immediately upgrade to a version of the json gem that includes the fix for this vulnerability. Consult the affected components section for the specific version ranges that require updating.

Where can I find more information about this vulnerability?

Refer to the provided sources for detailed information and updates on this vulnerability.

Sources

Join the 0Day waitlist →

← Back to all threats