Vulnerabilities in Ruby
32 resultsVexday analysis
Ruby registra 9 vulnerabilidades na base do Vexday, todas de severidade abaixo de crítica, sem exploração ativa documentada (KEV). A fraqueza dominante é CWE-400 (controle inadequado de recursos), indicando risco moderado de negação de serviço; a ausência de atualizações nos últimos 90 dias sugere que as ameaças conhecidas não evoluíram recentemente, mantendo o panorama estável.
CVE-2025-61594LOWURI Credential Leakage Bypass over CVE-2025-27221EPSS 0.5%CVE-2026-47240MEDIUMNet::IMAP: Command Injection via non-synchronizing literal in "raw" argumentEPSS 0.5%CVE-2025-43857MEDIUMnet-imap rubygem vulnerable to possible DoS by memory exhaustionEPSS 0.5%CVE-2026-42257MEDIUMnet-imap: Command Injection via "raw" arguments to multiple commandsEPSS 0.4%CVE-2025-6442MEDIUMRuby WEBrick read_header HTTP Request Smuggling VulnerabilityEPSS 0.4%CVE-2026-42245LOWnet-imap: Quadratic complexity when reading response literalsEPSS 0.4%CVE-2026-42246HIGHnet-imap vulnerable to STARTTLS stripping via invalid response timingEPSS 0.3%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.3%CVE-2026-42256MEDIUMnet-imap: Denial of service via high iteration count for `SCRAM-*` authenticationEPSS 0.3%CVE-2026-47241LOWNet::IMAP: Denial of Service via incomplete raw argument validationEPSS 0.2%CVE-2025-58767LOWREXML has a DoS condition when parsing malformed XML fileEPSS 0.2%CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.1%