Skip to main content

Vendor/product archive

ruby-lang / ruby CVEs

Beta · best-effort

112 CVEs tagged to ruby-lang / ruby20 Critical, 42 High, 50 Medium, 0 Low, 0 Unrated.

CVE-2026-46727

Published May 22, 2026

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrin…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27220

Published Mar 4, 2025

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-26142

Published Feb 27, 2024

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2338

Published Sep 29, 2022

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28738

Published May 9, 2022

A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-16254

Published Nov 26, 2019

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an at…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 112 CVEsPage 1 of 5