<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:09:33.535295+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:3020</id>
    <title>ALSA-2021:3020 — Important: ruby:2.7 security update</title>
    <updated>2026-10-03T17:09:33.657140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc and 21 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source (CVE-2020-36327)</p>
<p>* rubygem-rdoc: Command injection vulnerability in RDoc (CVE-2021-31799)</p>
<p>* ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host (CVE-2021-31810)</p>
<p>* ruby: StartTLS stripping vulnerability in Net::IMAP (CVE-2021-32066)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:3020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04264</id>
    <title>bdu:2021-04264</title>
    <updated>2026-10-03T17:09:33.657271+00:00</updated>
    <content>bdu:2021-04264</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-32066</id>
    <title>Withdrawn: BELL-CVE-2021-32066 — CVE-2021-32066 does not affect BellSoft software</title>
    <updated>2026-10-03T17:09:33.657290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-32066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-ruby-2021-32066</id>
    <title>BIT-ruby-2021-32066</title>
    <updated>2026-10-03T17:09:33.657306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: ruby</p>
<p>An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-ruby-2021-32066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-sh27100</id>
    <title>CLEANSTART-2026-SH27100 — Security fix for CVE-2021-32066 applied in: ruby 2.7.4-r0</title>
    <updated>2026-10-03T17:09:33.657328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby</p>
<p>Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-sh27100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-27817</id>
    <title>EUVD-2026-27817</title>
    <updated>2026-10-03T17:09:33.657347+00:00</updated>
    <content>EUVD-2026-27817</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-27817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32066</id>
    <title>fkie_cve-2021-32066</title>
    <updated>2026-10-03T17:09:33.657358+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gx49-h5r3-q3xj</id>
    <title>GHSA-gx49-h5r3-q3xj</title>
    <updated>2026-10-03T17:09:33.657380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gx49-h5r3-q3xj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32066</id>
    <title>gsd-2021-32066</title>
    <updated>2026-10-03T17:09:33.657395+00:00</updated>
    <content>gsd-2021-32066</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-32066</id>
    <title>msrc_CVE-2021-32066 — An issue was discovered in Ruby through 2.6.7 2.7.x through 2.7.3 and 3.x through 3.0.1. Net::IMAP does not raise an ex…</title>
    <updated>2026-10-03T17:09:33.657406+00:00</updated>
    <content>msrc_CVE-2021-32066</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-32066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1306</id>
    <title>OESA-2021-1306 — ruby security update</title>
    <updated>2026-10-03T17:09:33.657424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ruby, openEuler:20.03-LTS-SP2: ruby</p>
<p>Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).

Security Fix(es):

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.(CVE-2021-31799)

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).(CVE-2021-31810)

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a &amp;quot;StartTLS stripping attack.&amp;quot;(CVE-2021-32066)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1535-1</id>
    <title>openSUSE-SU-2021:1535-1 — Security update for ruby2.5</title>
    <updated>2026-10-03T17:09:33.657453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby2.5</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1535-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3559</id>
    <title>RHSA-2021:3559 — Red Hat Security Advisory: rh-ruby27-ruby security update</title>
    <updated>2026-10-03T17:09:33.657470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source rubygem-rdoc: Command injection vulnerability in RDoc ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host ruby: StartTLS stripping vulnerability in Net::IMAP</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:3837-1</id>
    <title>SUSE-SU-2021:3837-1 — Security update for ruby2.1</title>
    <updated>2026-10-03T17:09:33.657490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby2.1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:3837-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-32066</id>
    <title>UBUNTU-CVE-2021-32066</title>
    <updated>2026-10-03T17:09:33.657505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:20.04:LTS: ruby2.7</p>
<p>An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-32066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1305</id>
    <title>WID-SEC-W-2022-1305 — Ruby: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:09:33.657527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um Sicherheitsvorkehrungen zu umgehen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1305"/>
  </entry>
</feed>
