First published: Wed Mar 12 2025(Updated: )
### Impact A specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions 2.10.0 and 2.10.1 are impacted. Older versions are not. ### Patches Version 2.10.2 fixes the problem. ### Workarounds None.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/json | >=2.10.0<=2.10.1 | 2.10.2 |
JSON Ruby | >=2.10.0<2.10.2 | |
Ruby-lang Javascript Object Notation Ruby | >=2.10.0 <2.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-27788 is considered to be moderate due to its potential to cause crashes.
To fix CVE-2025-27788, upgrade the Ruby JSON gem to version 2.10.2 or later.
CVE-2025-27788 affects Ruby JSON versions from 2.10.0 up to, but not including, 2.10.2.
CVE-2025-27788 introduces an out of bounds read vulnerability that may lead to application crashes.
No, version 2.10.0 of Ruby JSON is not safe and is vulnerable to CVE-2025-27788.