ruby
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting ruby.
- CVE-2026-80213An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octet...4.0
- CVE-2026-80212An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new cla...7.5
- CVE-2026-71847Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
- CVE-2026-54696Ruby JSON: JSON generator heap buffer overflow when streaming to an IO3.7
- CVE-2026-47242Net::IMAP: Command Injection via ID command argument
- CVE-2026-47240Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
- CVE-2026-47241Net::IMAP: Denial of Service via incomplete raw argument validation
- CVE-2026-42258net-imap: Command Injection via unvalidated Symbol inputs5.3
- CVE-2026-42257net-imap: Command Injection via "raw" arguments to multiple commands9.8
- CVE-2026-42256net-imap: Denial of service via high iteration count for `SCRAM-*` authentication6.5
- CVE-2026-42245net-imap: Quadratic complexity when reading response literals7.5
- CVE-2026-42246net-imap vulnerable to STARTTLS stripping via invalid response timing7.4
- CVE-2026-41316ERB has an @_init deserialization guard bypass via def_module / def_method / def_class8.1
- CVE-2026-27820zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption9.8
- CVE-2026-33210Ruby JSON has a format string injection vulnerability9.1