📦

json

Vendor: ruby-lang

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.13% Exploit Prob.
Latest CVE CVE-2026-33210 Mar 20

Security Vulnerability Index

Page 1 / 1
8.3 CVSS

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

EPSS: 0.04%
7.2 CVSS

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

EPSS: 0.45%
7.5 CVSS
CVE-2020-10663
Exploit Found

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

EPSS: 5.89%