THREAT OPS › Threat News › [GHSA] GHSA-9hj4-r449-hfvc (low) — Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
[GHSA] GHSA-9hj4-r449-hfvc (low) — Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
GHSA-9hj4-r449-hfvc Severity: low CVE: CVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
### Summary
Ruby's JSON native C extension clears the consumed `JSON::ResumableParser` input buffer but leaves `state.start`, `state.cursor`, and `state.end` pointing into released storage.
When `partial_value` rec
MITRE ATT&CK techniques
- Manual ModificationAML.T0043.003
Indicators of compromise
- 07bf8d47b115e45d6145d0447ab6c1c0255e4a7e9b2fb55c3c9a0e24406134acsha256
- fd61def38b9bb859fee7eec8e7d3143600e5b347sha1
- CVE-2026-71847cve
Original source: https://github.com/advisories/GHSA-9hj4-r449-hfvc