A high-severity denial-of-service flaw tracked as CVE-2026-71847 was disclosed in the Ruby json package, affecting versions 2.20.0 through before 2.21.2. The bug resides in the native C extension behind JSON::ResumableParser, where truncated streaming JSON containing duplicate object keys can cause the parser to clear its input buffer while leaving stale internal pointers behind, creating a heap-use-after-free condition classified as CWE-416.
If an application accepts attacker-controlled JSON streams and later calls partial_value on the incomplete input, the parser can perform pointer operations on freed memory in its warning-handling path and crash the Ruby worker process. The issue impacts availability rather than confidentiality or integrity, and the fix in json 2.21.2 clears the freed buffer, nullifies parser state pointers, and adjusts warning generation logic to avoid cursor calculations when parser state is still present.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-71847 was newly received by security-advisories@github.com. The issue describes a denial-of-service vulnerability in Ruby JSON's native extension that can crash a Ruby process via crafted truncated duplicate-key JSON streams.
The Ruby JSON package fixed a heap-use-after-free flaw in JSON::ResumableParser by version 2.21.2. The patch nullifies parser state pointers after freeing the buffer and changes warning emission logic to avoid cursor position calculations on freed memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.