Количество 22
Количество 22
RLSA-2026:20606
Important: ruby4.0 security update
RLSA-2026:20596
Important: ruby:4.0 security update
ELSA-2026-20606
ELSA-2026-20606: ruby4.0 security update (IMPORTANT)
ELSA-2026-20596
ELSA-2026-20596: ruby:4.0 security update (IMPORTANT)
CVE-2026-33210
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.
CVE-2026-33210
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.
CVE-2026-33210
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.
CVE-2026-33210
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to be ...
CVE-2026-41316
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
CVE-2026-41316
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
CVE-2026-41316
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
CVE-2026-41316
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was ...
GHSA-3m6g-2423-7cp3
Ruby JSON has a format string injection vulnerability
RLSA-2026:20614
Important: ruby:3.3 security update
RLSA-2026:18065
Important: ruby security update
RLSA-2026:18039
Important: ruby security update
RLSA-2026:18030
Important: ruby:3.3 security update
GHSA-q339-8rmv-2mhv
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
ELSA-2026-20614
ELSA-2026-20614: ruby:3.3 security update (IMPORTANT)
ELSA-2026-18065
ELSA-2026-18065: ruby security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:20606 Important: ruby4.0 security update | около 2 месяцев назад | |||
RLSA-2026:20596 Important: ruby:4.0 security update | 2 месяца назад | |||
ELSA-2026-20606 ELSA-2026-20606: ruby4.0 security update (IMPORTANT) | 16 дней назад | |||
ELSA-2026-20596 ELSA-2026-20596: ruby:4.0 security update (IMPORTANT) | около 1 месяца назад | |||
CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to be ... | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-41316 ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-41316 ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-41316 ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-41316 ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was ... | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
GHSA-3m6g-2423-7cp3 Ruby JSON has a format string injection vulnerability | 1% Низкий | 5 месяцев назад | ||
RLSA-2026:20614 Important: ruby:3.3 security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:18065 Important: ruby security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:18039 Important: ruby security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:18030 Important: ruby:3.3 security update | 1% Низкий | 3 месяца назад | ||
GHSA-q339-8rmv-2mhv ERB has an @_init deserialization guard bypass via def_module / def_method / def_class | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
ELSA-2026-20614 ELSA-2026-20614: ruby:3.3 security update (IMPORTANT) | 1% Низкий | 2 месяца назад | ||
ELSA-2026-18065 ELSA-2026-18065: ruby security update (IMPORTANT) | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу