|
| 1 | +--- |
| 2 | +gem: json |
| 3 | +cve: 2026-71847 |
| 4 | +ghsa: 9hj4-r449-hfvc |
| 5 | +url: https://nvd.nist.gov/vuln/detail/CVE-2026-71847 |
| 6 | +title: Ruby JSON - JSON::ResumableParser#partial_value dereferences |
| 7 | + a freed input buffer and crashes on truncated duplicate-key streams |
| 8 | +date: 2026-08-07 |
| 9 | +description: | |
| 10 | + ### Summary |
| 11 | +
|
| 12 | + Ruby's JSON native C extension clears the consumed `JSON::ResumableParser` |
| 13 | + input buffer but leaves `state.start`, `state.cursor`, and `state.end` |
| 14 | + pointing into released storage. |
| 15 | +
|
| 16 | + When `partial_value` reconstructs an incomplete object containing |
| 17 | + duplicate keys, the duplicate-key warning path calls `cursor_position`, |
| 18 | + which dereferences those stale pointers. This results in a |
| 19 | + heap-use-after-free and can terminate the Ruby process. |
| 20 | +
|
| 21 | + An attacker who can supply JSON stream data to an application using |
| 22 | + `JSON::ResumableParser` may cause process termination when the |
| 23 | + application calls `partial_value` on incomplete attacker-controlled |
| 24 | + input containing duplicate object keys. |
| 25 | +
|
| 26 | + The issue was reproduced in the native C extension from the official |
| 27 | + RubyGems releases: |
| 28 | +
|
| 29 | + * JSON 2.20.0 |
| 30 | + * JSON 2.21.0 |
| 31 | + * JSON 2.21.1 |
| 32 | +
|
| 33 | + The attached evidence demonstrates: |
| 34 | +
|
| 35 | + * an AddressSanitizer-confirmed heap-use-after-free; |
| 36 | + * a native `SIGSEGV` using the official JSON 2.21.1 RubyGem; |
| 37 | + * an end-to-end loopback TCP attacker/victim reproduction; |
| 38 | + * four differential controls; |
| 39 | + * successful execution after applying a tested patch control. |
| 40 | +
|
| 41 | + This was originally reported privately through Ruby's HackerOne program |
| 42 | + as report `#3867755`. A Ruby maintainer independently confirmed |
| 43 | + reproduction of the ASan failure and requested that further |
| 44 | + coordination continue through this private advisory. |
| 45 | +
|
| 46 | + No code execution or information disclosure is claimed. |
| 47 | +
|
| 48 | + ### Impact |
| 49 | +
|
| 50 | + This is a use-after-free that can result in native Ruby process termination. |
| 51 | +
|
| 52 | + An attacker must be able to supply JSON stream data to an application that: |
| 53 | +
|
| 54 | + 1. uses `JSON::ResumableParser`; |
| 55 | + 2. processes attacker-controlled streaming input; |
| 56 | + 3. calls `partial_value` after parsing an incomplete document |
| 57 | + containing duplicate object keys. |
| 58 | +
|
| 59 | + In network-facing deployments meeting these conditions, an attacker |
| 60 | + can cause process termination and denial of service. |
| 61 | +
|
| 62 | + The release-build crash was reproduced consistently in the tested |
| 63 | + Linux environment. The AddressSanitizer result confirms the underlying |
| 64 | + heap-use-after-free independently of normal allocator behavior. |
| 65 | +
|
| 66 | + The demonstrated impact is: |
| 67 | +
|
| 68 | + ```text |
| 69 | + Denial of service through native process termination |
| 70 | + ``` |
| 71 | +
|
| 72 | + No confidentiality impact, integrity impact, arbitrary code execution, |
| 73 | + or information disclosure is claimed. |
| 74 | +cvss_v4: 8.7 |
| 75 | +unaffected_versions: |
| 76 | + - "< 2.20.0" |
| 77 | +patched_versions: |
| 78 | + - ">= 2.21.2" |
| 79 | +related: |
| 80 | + url: |
| 81 | + - https://nvd.nist.gov/vuln/detail/CVE-2026-71847 |
| 82 | + - https://rubygems.org/gems/json/versions/2.21.2 |
| 83 | + - https://github.com/ruby/json/blob/master/CHANGES.md#2026-07-31-2212 |
| 84 | + - https://github.com/ruby/json/releases/tag/v2.21.2 |
| 85 | + - https://advisories.gitlab.com/gem/json/CVE-2026-71847 |
| 86 | + - https://osv.dev/vulnerability/GHSA-9hj4-r449-hfvc |
| 87 | + - https://github.com/ruby/json/security/advisories/GHSA-9hj4-r449-hfvc |
| 88 | + - https://github.com/advisories/GHSA-9hj4-r449-hfvc |
| 89 | +notes: | |
| 90 | + - "Low" severity in global GHSA URL. |
| 91 | + - cvss_v4 from nvd.nist.gov URL. |
| 92 | + - Watch for Ruby's HackerOne #3867755. |
0 commit comments