Json
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Json, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Json CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High5
- Medium1
- Low1
Latest CVEs
The 10 most recently published vulnerabilities affecting Json.
- CVE-2026-71847Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams—
- CVE-2026-54696Ruby JSON: JSON generator heap buffer overflow when streaming to an IO3.7
- CVE-2026-33210Ruby JSON has a format string injection vulnerability9.1
- CVE-2025-27788Ruby JSON Parser has Out-of-bounds Read7.5
- CVE-2022-23460Stack overflow in Jsonxx5.9
- CVE-2022-23459Double free or Use after Free in Value class of Jsonxx8.1
- CVE-2020-7712Command Injection7.2
- CVE-2020-10663The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269...7.5
- CVE-2018-17072JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y.9.8
- CVE-2013-0269The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection m...7.5
Product grouping is registry-driven, with AI assist and human review. How it works