GEM · AUGUST 2026 · EARLY WARNING

Ruby JSON Gem Vulnerability: Critical CVE Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
json (gem)
Affected versions
>= 2.18.0, < 2.19.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.16.0, < 2.17.1.2 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.14.0, < 2.15.2.1 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.20.0, < 2.21.2 or >= 2.20.0, <= 2.20.0 or >= 2.21.0, <= 2.21.0 or >= 2.21.1, <= 2.21.1 or >= 2.10.0, < 2.10.2 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or < 2.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.5.5, <= 1.5.5 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.6.8, <= 1.6.8 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6 or >= 1.7.7, <= 1.7.7 or >= 1.8.0, <= 1.8.0 or >= 1.8.1, <= 1.8.1 or >= 1.8.2, <= 1.8.2 or >= 1.8.3, <= 1.8.3 or >= 1.8.5, <= 1.8.5 or >= 1.8.6, <= 1.8.6 or >= 2.0.0, <= 2.0.0 or >= 2.0.1, <= 2.0.1 or >= 2.0.2, <= 2.0.2 or >= 2.0.3, <= 2.0.3 or >= 2.0.4, <= 2.0.4 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.9.0, < 2.19.9 or >= 2.10.0, <= 2.10.0 or >= 2.10.1, <= 2.10.1 or >= 2.10.2, <= 2.10.2 or >= 2.11.0, <= 2.11.0 or >= 2.11.1, <= 2.11.1 or >= 2.11.2, <= 2.11.2 or >= 2.11.3, <= 2.11.3 or >= 2.12.0, <= 2.12.0 or >= 2.12.1, <= 2.12.1 or >= 2.12.2, <= 2.12.2 or >= 2.13.0, <= 2.13.0 or >= 2.13.1, <= 2.13.1 or >= 2.13.2, <= 2.13.2 or >= 2.14.0, <= 2.14.0 or >= 2.14.1, <= 2.14.1 or >= 2.15.0, <= 2.15.0 or >= 2.15.1, <= 2.15.1 or >= 2.15.2, <= 2.15.2 or >= 2.15.2.1, <= 2.15.2.1 or >= 2.16.0, <= 2.16.0 or >= 2.17.0, <= 2.17.0 or >= 2.17.1, <= 2.17.1 or >= 2.17.1.2, <= 2.17.1.2 or >= 2.18.0, <= 2.18.0 or >= 2.18.1, <= 2.18.1 or >= 2.19.0, <= 2.19.0 or >= 2.19.1, <= 2.19.1 or >= 2.19.2, <= 2.19.2 or >= 2.19.3, <= 2.19.3 or >= 2.19.4, <= 2.19.4 or >= 2.19.5, <= 2.19.5 or >= 2.19.6, <= 2.19.6 or >= 2.19.7, <= 2.19.7 or >= 2.19.8, <= 2.19.8 or >= 2.9.0, <= 2.9.0 or >= 2.9.1, <= 2.9.1 or < 1.5.5 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.2, <= 1.0.2 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.1.4, <= 1.1.4 or >= 1.1.5, <= 1.1.5 or >= 1.1.6, <= 1.1.6 or >= 1.1.7, <= 1.1.7 or >= 1.1.8, <= 1.1.8 or >= 1.1.9, <= 1.1.9 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.2.3, <= 1.2.3 or >= 1.2.4, <= 1.2.4 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.4.4, <= 1.4.4 or >= 1.4.5, <= 1.4.5 or >= 1.4.6, <= 1.4.6 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, < 1.6.8 or >= 1.6.0, <= 1.6.0 or >= 1.6.0.1, <= 1.6.0.1 or >= 1.6.1, <= 1.6.1 or >= 1.6.2, <= 1.6.2 or >= 1.6.3, <= 1.6.3 or >= 1.6.4, <= 1.6.4 or >= 1.6.5, <= 1.6.5 or >= 1.6.6, <= 1.6.6 or >= 1.6.7, <= 1.6.7 or >= 1.7.0, < 1.7.7 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.7.2, <= 1.7.2 or >= 1.7.3, <= 1.7.3 or >= 1.7.4, <= 1.7.4 or >= 1.7.5, <= 1.7.5 or >= 1.7.6, <= 1.7.6
Patched version
Not yet available
GHSA-9HJ4-R449-HFVC

An early warning has been issued for a critical vulnerability in the Ruby JSON gem. The vulnerability, which is under investigation, may cause crashes in affected versions.

What happened

The Ruby JSON gem, specifically its native C extension, reportedly has an issue where the consumed input buffer is cleared but state pointers remain in released storage. This leads to a heap-use-after-free condition and potential process termination. The vulnerability has been tracked under GHSA-9HJ4-R449-HFVC and is not yet confirmed to be exploited in the wild.

Affected versions of the json gem range from 0.4.0 to 2.21.2 with certain exclusions. The vulnerability appears to affect a wide range of versions, making it crucial for users to check their specific version against the provided range.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If json is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if you are using a version of the json gem within the specified affected range.

What should I do right now?

Check your json gem version and upgrade to a fixed version if available. Apply any provided patches and monitor updates from the primary sources.

Is there an official fix available?

The primary sources should be consulted for the latest information on available fixes.

Sources

Join the 0Day waitlist →

← Back to all threats