HIGH7.5
GHSA-9m3q-rhmv-5q44
Out-of-bounds Read in Ruby JSON Parser
Quick fix
GHSA-9m3q-rhmv-5q44 — json: upgrade to the fixed version with the command below.
bundle update jsonDetails
### Impact
A specially crafted document could cause an out of bound read, most likely resulting in a crash.
Versions 2.10.0 and 2.10.1 are impacted. Older versions are not.
### Patches
Version 2.10.2 fixes the problem.
### Workarounds
None.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ruby/json/security/advisories/GHSA-9m3q-rhmv-5q44[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27788[ADVISORY]
- https://github.com/ruby/json/commit/c56db31f800d5d508389793e69682f99749dbadf[WEB]
- https://github.com/ruby/json[PACKAGE]
- https://github.com/ruby/json/releases/tag/v2.10.2[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2025-27788.yml[WEB]