Ruby JSON Gem Vulnerability: Critical Heap-Use-After-Free Issue
- Severity
- HIGH
- Affected component
- json (gem)
- Affected versions
- >= 2.18.0, < 2.19.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.16.0, < 2.17.1.2 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.14.0, < 2.15.2.1 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.20.0, < 2.21.2 or >= 2.20.0, <= 2.20.0 or >= 2.21.0, <= 2.21.0 or >= 2.21.1, <= 2.21.1 or >= 2.10.0, < 2.10.2 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or < 2.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.5.5, <= 1.5.5 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.6.8, <= 1.6.8 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6 or >= 1.7.7, <= 1.7.7 or >= 1.8.0, <= 1.8.0 or >= 1.8.1, <= 1.8.1 or >= 1.8.2, <= 1.8.2 or >= 1.8.3, <= 1.8.3 or >= 1.8.5, <= 1.8.5 or >= 1.8.6, <= 1.8.6 or >= 2.0.0, <= 2.0.0 or >= 2.0.1, <= 2.0.1 or >= 2.0.2, <= 2.0.2 or >= 2.0.3, <= 2.0.3 or >= 2.0.4, <= 2.0.4 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.9.0, < 2.19.9 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or >= 2.10.2, <= 2.10.2 or >= 2.11.0, <= 2.11.0 or >= 2.11.1, <= 2.11.1 or >= 2.11.2, <= 2.11.2 or >= 2.11.3, <= 2.11.3 or >= 2.12.0, <= 2.12.0 or >= 2.12.1, <= 2.12.1 or >= 2.12.2, <= 2.12.2 or >= 2.13.0, <= 2.13.0 or >= 2.13.1, <= 2.13.1 or >= 2.13.2, <= 2.13.2 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.15.2.1, <= 2.15.2.1 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.17.1.2, <= 2.17.1.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.19.2, <= 2.19.2 or >= 2.19.3, <= 2.19.3 or >= 2.19.4, <= 2.19.4 or >= 2.19.5, <= 2.19.5 or >= 2.19.6, <= 2.19.6 or >= 2.19.7, <= 2.19.7 or >= 2.19.8, <= 2.19.8 or >= 2.9.0, <= 2.9.0 or >= 2.9.1, <= 2.9.1 or < 1.5.5 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, < 1.6.8 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.7.0, < 1.7.7 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6
- Patched version
- Not yet available
A confirmed critical vulnerability in Ruby's JSON gem could lead to a heap-use-after-free condition and potential process termination. Users of affected versions should take immediate action.
What happened
The vulnerability, tracked as GHSA-9HJ4-R449-HFVC, arises from the JSON native C extension improperly handling consumed input buffers. This results in state pointers referencing released storage, leading to a heap-use-after-free condition. The issue has been confirmed by multiple independent sources and is rated as HIGH severity.
The vulnerability affects a wide range of versions of the json gem, including but not limited to versions >= 2.18.0, < 2.19.2 and >= 2.16.0, < 2.17.1.2. The specific versions impacted are detailed in the affected components section. No exploitation in the wild has been reported at this time.
What to do about it
- Upgrade to a version of the json gem that includes the fix for this issue.
- Consult the affected components section for the specific version ranges that require updating.
- Monitor the provided sources for updates on patched versions and further details.
How 0Day would have caught this
json is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using any version of the json gem within the specified vulnerable ranges, as detailed in the affected components section.
What should I do right now?
Immediately upgrade to a version of the json gem that includes the fix for this vulnerability. Consult the affected components section for the specific version ranges that require updating.
Where can I find more information about this vulnerability?
Refer to the provided sources for detailed information and updates on this vulnerability.
Sources
- [GHSA-9hj4-r449-hfvc] Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
- [CVE-2026-72748] CVSS 9.1 CRITICAL
- [CVE-2026-72851] CVSS 10.0 CRITICAL
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
- BdThemes plugins supply-chain hack creates rogue WordPress admins