Object deserialization attacks using Ruby's Oj JSON parser

3 JNRowe 1 7/27/2025, 12:19:12 AM hezmatt.org ↗

Comments (1)

Lio · 4h ago
I think that in 2025 the standard ruby JSON library is now finally faster than Oj so it’s pretty it’s one more external dependency we can remove.

Thanks for your service OJ, you were very helpful for a long time.