Ruby JSON Gem Vulnerability: Critical CVE Under Investigation
- Severity
- HIGH
- Affected component
- json (gem)
- Affected versions
- >= 2.18.0, < 2.19.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.16.0, < 2.17.1.2 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.14.0, < 2.15.2.1 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.20.0, < 2.21.2 or >= 2.20.0, <= 2.20.0 or >= 2.21.0, <= 2.21.0 or >= 2.21.1, <= 2.21.1 or >= 2.10.0, < 2.10.2 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or < 2.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.5.5, <= 1.5.5 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.6.8, <= 1.6.8 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6 or >= 1.7.7, <= 1.7.7 or >= 1.8.0, <= 1.8.0 or >= 1.8.1, <= 1.8.1 or >= 1.8.2, <= 1.8.2 or >= 1.8.3, <= 1.8.3 or >= 1.8.5, <= 1.8.5 or >= 1.8.6, <= 1.8.6 or >= 2.0.0, <= 2.0.0 or >= 2.0.1, <= 2.0.1 or >= 2.0.2, <= 2.0.2 or >= 2.0.3, <= 2.0.3 or >= 2.0.4, <= 2.0.4 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.9.0, < 2.19.9 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or >= 2.10.2, <= 2.10.2 or >= 2.11.0, <= 2.11.0 or >= 2.11.1, <= 2.11.1 or >= 2.11.2, <= 2.11.2 or >= 2.11.3, <= 2.11.3 or >= 2.12.0, <= 2.12.0 or >= 2.12.1, <= 2.12.1 or >= 2.12.2, <= 2.12.2 or >= 2.13.0, <= 2.13.0 or >= 2.13.1, <= 2.13.1 or >= 2.13.2, <= 2.13.2 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.15.2.1, <= 2.15.2.1 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.17.1.2, <= 2.17.1.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.19.2, <= 2.19.2 or >= 2.19.3, <= 2.19.3 or >= 2.19.4, <= 2.19.4 or >= 2.19.5, <= 2.19.5 or >= 2.19.6, <= 2.19.6 or >= 2.19.7, <= 2.19.7 or >= 2.19.8, <= 2.19.8 or >= 2.9.0, <= 2.9.0 or >= 2.9.1, <= 2.9.1 or < 1.5.5 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, < 1.6.8 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.7.0, < 1.7.7 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the Ruby JSON gem. The vulnerability, which is under investigation, may cause crashes in affected versions.
What happened
The Ruby JSON gem, specifically its native C extension, reportedly has an issue where the consumed input buffer is cleared but state pointers remain in released storage. This leads to a heap-use-after-free condition and potential process termination. The vulnerability has been tracked under GHSA-9HJ4-R449-HFVC and is not yet confirmed to be exploited in the wild.
Affected versions of the json gem range from 0.4.0 to 2.21.2 with certain exclusions. The vulnerability appears to affect a wide range of versions, making it crucial for users to check their specific version against the provided range.
What to do about it
- Check your current version of the json gem against the affected range provided in the threat data.
- Upgrade to a version of the json gem that includes the fix if one is available.
- Apply the patch if it is provided by the maintainers.
- If no official fix has been published yet, monitor the primary sources for updates.
How 0Day would have caught this
json is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if you are using a version of the json gem within the specified affected range.
What should I do right now?
Check your json gem version and upgrade to a fixed version if available. Apply any provided patches and monitor updates from the primary sources.
Is there an official fix available?
The primary sources should be consulted for the latest information on available fixes.