Vulnerabilidades em ruby
35 resultadosAnálise Vexday
Ruby apresenta 23 vulnerabilidades catalogadas, com 10 delas publicadas nos últimos 90 dias, indicando risco em evolução. Não há registros de exploração ativa em campo (KEV) nem vulnerabilidades críticas no momento, mas a fraqueza dominante em Denial of Service (CWE-400) sinaliza potencial para impacto operacional. O volume recente de CVEs recomenda monitoramento contínuo das mitigações disponíveis.
CVE-2025-24294HIGHThe attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressEPSS 0.6%CVE-2026-27820LOWzlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruptionEPSS 0.6%CVE-2026-47240MEDIUMNet::IMAP: Command Injection via non-synchronizing literal in "raw" argumentEPSS 0.5%CVE-2025-6442MEDIUMRuby WEBrick read_header HTTP Request Smuggling VulnerabilityEPSS 0.5%CVE-2025-43857MEDIUMnet-imap rubygem vulnerable to possible DoS by memory exhaustionEPSS 0.5%CVE-2026-42257MEDIUMnet-imap: Command Injection via "raw" arguments to multiple commandsEPSS 0.4%CVE-2026-42245LOWnet-imap: Quadratic complexity when reading response literalsEPSS 0.4%CVE-2026-71847HIGHRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsEPSS 0.4%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.4%CVE-2026-80213MEDIUMAn issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet EPSS 0.4%CVE-2026-42246HIGHnet-imap vulnerable to STARTTLS stripping via invalid response timingEPSS 0.3%CVE-2026-42256MEDIUMnet-imap: Denial of service via high iteration count for `SCRAM-*` authenticationEPSS 0.3%CVE-2025-58767LOWREXML has a DoS condition when parsing malformed XML fileEPSS 0.2%CVE-2026-47241LOWNet::IMAP: Denial of Service via incomplete raw argument validationEPSS 0.2%CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.1%