Skip to main content

Vendor archive

jruby CVEs

Beta · best-effort

5 CVEs tagged to vendor jruby0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-46551

Published May 7, 2025

JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRub…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2012-5370

Published Nov 28, 2012

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1330

Published Nov 23, 2012

The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4838

Published Dec 30, 2011

JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1