RubySec

Providing security resources for the Ruby community

GHSA-wr87-m4jw-29x5 (dalli): Per-request raw and the JSON serializer don't prevent unsafe deserialization

Per-request raw and the JSON serializer don't prevent unsafe deserialization

Published: October 05, 2026

SECURITY IDENTIFIERS

GEM

dalli

PATCHED VERSIONS

~> 3.2.13 ~> 4.3.7 ~> 5.0.10 ~> 5.1.4 >= 5.2.2

DESCRIPTION

  1. Per-request raw: true was ignored by some read methods, which still ran the configured serializer's load (Marshal by default) on values whose flags say they're serialized: in 5.1 and 5.2, get_multi, get_multi_cas, get_multi_with_metadata, get_cas and get_with_metadata; in 5.0, get_with_metadata; in 4.x, get, gat and fetch with the binary protocol, and get_with_metadata; in 3.x, get, gat and fetch.
  2. serializer: JSON resolves to JSON.load. With the json gem before 3.0, JSON.load honors json_class when the json additions are loaded, so a crafted value can instantiate classes that define json_create.

Exploiting either requires write access to the memcached instance and an application relying on per-request raw: true or serializer: JSON to avoid unsafe deserialization. Patched versions add Dalli::JSONSerializer, which reads with JSON.parse.

The first fix (5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12) was incomplete: on 5.0, 4.3 and 3.2, cas and cas! (and fetch_with_lock on 5.0, and on 4.3 with the meta protocol) still deserialized values read with raw: true, and on every line but 3.2 a raw read still honored flags a reply carried unasked. Both are fixed in 5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13.

Workarounds

Use a serializer that only parses data, such as one wrapping JSON.parse, instead of serializer: JSON.

RELATED