Ruby
- Products in analyzed data
- 11
- Catalog vulnerabilities
- 36
Severity across 36 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 36 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, Ruby recorded 8 security vulnerabilities in the last 90 days across 4 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, net-imap had the most security vulnerabilities in the Ruby ecosystem, with 3 vulnerabilities—approximately 37.5% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-82455RubyGems before 4.0.13 Path Traversal via Symlink Resolution | Exploitation statusNot known exploited | FixYes | Affected productrubygems | Published08/29/2026 | SeverityMedium |
CVE-2026-80213CVE-2026-80213 | Exploitation statusNot known exploited | FixYes | Affected productresolv | Published08/27/2026 | SeverityMedium |
CVE-2026-80212CVE-2026-80212 | Exploitation statusNot known exploited | FixYes | Affected productresolv | Published08/27/2026 | SeverityHigh |
CVE-2026-71847Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams | Exploitation statusPublic exploit | FixYes | Affected productjson | Published08/07/2026 | SeverityHigh |
CVE-2026-54696Ruby JSON: JSON generator heap buffer overflow when streaming to an IO | Exploitation statusPublic exploit | FixYes | Affected productjson | Published06/30/2026 | SeverityLow |
CVE-2026-47242Net::IMAP: Command Injection via ID command argument | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published06/22/2026 | SeverityMedium |
CVE-2026-47240Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published06/22/2026 | SeverityMedium |
CVE-2026-47241Net::IMAP: Denial of Service via incomplete raw argument validation | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published06/22/2026 | SeverityLow |
CVE-2026-42258net-imap: Command Injection via unvalidated Symbol inputs | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published05/09/2026 | SeverityMedium |
CVE-2026-42257net-imap: Command Injection via "raw" arguments to multiple commands | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published05/09/2026 | SeverityMedium |
CVE-2026-42256net-imap: Denial of service via high iteration count for `SCRAM-*` authentication | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published05/09/2026 | SeverityMedium |
CVE-2026-42245net-imap: Quadratic complexity when reading response literals | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published05/09/2026 | SeverityLow |
CVE-2026-42246net-imap vulnerable to STARTTLS stripping via invalid response timing | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published05/09/2026 | SeverityHigh |
CVE-2026-41316ERB has an @_init deserialization guard bypass via def_module / def_method / def_class | Exploitation statusNot known exploited | FixNot confirmed | Affected producterb | Published04/24/2026 | SeverityHigh |
CVE-2026-27820zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption | Exploitation statusNot known exploited | FixYes | Affected productzlib | Published04/16/2026 | SeverityLow |
CVE-2026-33210Ruby JSON has a format string injection vulnerability | Exploitation statusNot known exploited | FixYes | Affected productjson | Published03/20/2026 | SeverityHigh |
CVE-2025-61594URI Credential Leakage Bypass over CVE-2025-27221 | Exploitation statusNot known exploited | FixYes | Affected producturi | Published12/30/2025 | SeverityLow |
CVE-2025-58767REXML has a DoS condition when parsing malformed XML file | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published09/17/2025 | SeverityLow |
CVE-2025-24294CVE-2025-24294 | Exploitation statusNot known exploited | FixYes | Affected productresolv | Published07/12/2025 | SeverityHigh |
CVE-2025-6442Ruby WEBrick read_header HTTP Request Smuggling Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productWEBrick | Published06/25/2025 | SeverityMedium |
CVE-2025-43857net-imap rubygem vulnerable to possible DoS by memory exhaustion | Exploitation statusNot known exploited | FixYes | Affected productnet-imap | Published04/28/2025 | SeverityMedium |
CVE-2025-27788Ruby JSON Parser has Out-of-bounds Read | Exploitation statusNot known exploited | FixNot confirmed | Affected productjson | Published03/12/2025 | SeverityHigh |
CVE-2025-25186Net::IMAP vulnerable to possible DoS by memory exhaustion | Exploitation statusPublic exploit | FixNot confirmed | Affected productnet-imap | Published02/10/2025 | SeverityMedium |
CVE-2024-49761REXML ReDoS vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published10/28/2024 | SeverityMedium |
CVE-2024-43398REXML denial of service vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published08/22/2024 | SeverityMedium |
CVE-2024-41946REXML DoS vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published08/01/2024 | SeverityMedium |
CVE-2024-41123REXML DoS vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published08/01/2024 | SeverityMedium |
CVE-2024-39908Denial of service in REXML | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published07/16/2024 | SeverityMedium |
CVE-2024-35176REXML contains a denial of service vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productrexml | Published05/16/2024 | SeverityMedium |
CVE-2015-1855CVE-2015-1855 | Exploitation statusNot confirmed | FixNot confirmed | Affected productRuby | Published11/29/2019 | SeverityUnknown |
CVE-2011-3624CVE-2011-3624 | Exploitation statusNot confirmed | FixNot confirmed | Affected productRuby | Published11/26/2019 | SeverityUnknown |
CVE-2013-6461CVE-2013-6461 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNokogiri gem | Published11/05/2019 | SeverityUnknown |
CVE-2013-6460CVE-2013-6460 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNokogiri gem | Published11/05/2019 | SeverityUnknown |
CVE-2016-2336CVE-2016-2336 | Exploitation statusNot confirmed | FixNot confirmed | Affected productRuby | Published01/06/2017 | SeverityUnknown |
CVE-2016-2337CVE-2016-2337 | Exploitation statusNot confirmed | FixNot confirmed | Affected productRuby | Published01/06/2017 | SeverityUnknown |
CVE-2016-2339CVE-2016-2339 | Exploitation statusNot confirmed | FixNot confirmed | Affected productRuby | Published01/06/2017 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan