RubySec

Providing security resources for the Ruby community

CVE-2025-27788 (json): Out-of-bounds Read in Ruby JSON Parser

ADVISORIES

GEM

json

SEVERITY

CVSS v3.x: 7.5 (High)

UNAFFECTED VERSIONS

  • < 2.10.0

PATCHED VERSIONS

  • >= 2.10.2

DESCRIPTION

Impact

A specially crafted document could cause an out of bound read, most likely resulting in a crash.

Versions 2.10.0 and 2.10.1 are impacted. Older versions are not.

Patches

Version 2.10.2 fixes the problem.

Workarounds

None.

RELATED