Yajl Ruby Project maintains a Ruby binding for the YAJL JSON parsing library, a narrowly scoped but widely embedded component used in applications that handle JSON serialization and deserialization. The vendor's disclosures reflect the parsing-oriented attack surface inherent to JSON handling in dynamic languages, where input validation and data transformation represent the primary exposure vectors. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yajl Ruby Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24795HIGH yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap mem | Apr 5, 2022 | 7.5 | 26 | NO | NO |
CVE-2017-16516HIGH In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode functio | Nov 3, 2017 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yajl Ruby Project.
Media articles that mention a CVE ID that affects a product developed by Yajl Ruby Project — matched by CVE ID, not by vendor name.