[Git][security-tracker-team/security-tracker][master] new ruby-oj issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Jul 2 11:41:25 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f1081788 by Moritz Muehlenhoff at 2026-07-02T12:41:05+02:00
new ruby-oj issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -981,21 +981,29 @@ CVE-2026-55721 (Storage Concentrator (SC & SCVM) is vulnerable to SQL injection
 CVE-2026-55223 (c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ...)
 	TODO: check
 CVE-2026-54903 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-475m-ph3x-64gp
 CVE-2026-54902 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-m578-w5vf-rfcm
 CVE-2026-54901 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-vwm4-62gf-x745
 CVE-2026-54900 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-9cv6-qcjw-4grx
 CVE-2026-54899 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-2cw7-v8ff-p88r
 CVE-2026-54898 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-q2gm-54r6-8fwm
 CVE-2026-54897 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-9ppp-w3g4-fh4q
 CVE-2026-54896 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-35w3-pjm6-wj95
 CVE-2026-54696 (Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2. ...)
 	TODO: check
 CVE-2026-54673 (electron-updater allows for automatic updates for Electron apps. Prior ...)
@@ -1003,11 +1011,14 @@ CVE-2026-54673 (electron-updater allows for automatic updates for Electron apps.
 CVE-2026-54672 (electron-updater allows for automatic updates for Electron apps. Prior ...)
 	NOT-FOR-US: electron-updater
 CVE-2026-54592 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-3m6q-jj5j-38c9
 CVE-2026-54502 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-3v45-f3vh-wg7m
 CVE-2026-54500 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
-	TODO: check
+	- ruby-oj 3.17.3-1
+	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-fm7p-mprw-wjm9
 CVE-2026-52868 (An unauthenticated attacker can read worklist records from a directory ...)
 	TODO: check
 CVE-2026-52198 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-1613 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1081788414160344748142eacd32b303ccc47e0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1081788414160344748142eacd32b303ccc47e0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/e9707d38/attachment.htm>


More information about the debian-security-tracker-commits mailing list