Skip to main content

Vendor archive

ruby-lang CVEs

Beta · best-effort

137 CVEs tagged to vendor ruby-lang20 Critical, 46 High, 65 Medium, 6 Low, 0 Unrated.

CVE-2026-46727

Published May 22, 2026

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrin…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42258

Published May 9, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable…

CVSS 5.8 · Medium
evidence mentions
30
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-42257

Published May 9, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw str…

CVSS 5.8 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-42256

Published May 9, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4,…

CVSS 6.0 · Medium
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2026-42245

Published May 9, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic tim…

CVSS 2.3 · Low
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-27820

Published Apr 16, 2026

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zli…

CVSS 1.7 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-33210

Published Mar 20, 2026

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of s…

CVSS 8.3 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-61594

Published Dec 30, 2025

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 serie…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-58767

Published Sep 17, 2025

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6442

Published Jun 25, 2025

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBr…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43857

Published Apr 28, 2025

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27788

Published Mar 12, 2025

JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resultin…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-27221

Published Mar 4, 2025

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained…

CVSS 3.2 · Low
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-27220

Published Mar 4, 2025

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-27219

Published Mar 4, 2025

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any li…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-41946

Published Aug 1, 2024

REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41123

Published Aug 1, 2024

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35176

Published May 16, 2024

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26142

Published Feb 27, 2024

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36617

Published Jun 29, 2023

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 137 CVEsPage 1 of 6