jmespath
Implements JMESPath for Ruby
Activity
- Latest release
- 3y ago
- Total releases
- 21
- Cadence
- ~8 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Oct 24, 2014
| Version | Released | |
|---|---|---|
1.6.2
patch
| ||
1.6.1
patch
| ||
1.6.0
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.4
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.3
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.2
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.3
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.0
initial
1 CVE
CVE-2022-32511
GHSA-5c5f-7vfq-3732
Jun 07, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. Affected versions
0.2.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.2
1.2.1
1.2.2
+ 7 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
Fixed in
1.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |