<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T19:13:13.649755+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:3821</id>
    <title>ALSA-2023:3821 — Moderate: ruby:2.7 security, bug fix, and enhancement update</title>
    <updated>2026-10-04T19:13:13.678389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc and 21 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>The following packages have been upgraded to a later upstream version: ruby (2.7). (BZ#2189465)</p>
<p>Security Fix(es):</p>
<p>* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:3821"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03834</id>
    <title>bdu:2023-03834</title>
    <updated>2026-10-04T19:13:13.678491+00:00</updated>
    <content>bdu:2023-03834</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-33621</id>
    <title>Withdrawn: BELL-CVE-2021-33621 — CVE-2021-33621 does not affect BellSoft software</title>
    <updated>2026-10-04T19:13:13.678509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-33621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-ruby-2021-33621</id>
    <title>BIT-ruby-2021-33621</title>
    <updated>2026-10-04T19:13:13.678524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: ruby</p>
<p>The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-ruby-2021-33621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0318</id>
    <title>certfr-2023-avi-0318 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;VMware&lt;/span&gt;. Elles permettent à un attaquan…</title>
    <updated>2026-10-04T19:13:13.678544+00:00</updated>
    <content>certfr-2023-avi-0318</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-jl84667</id>
    <title>CLEANSTART-2026-JL84667 — Security fix for CVE-2021-33621 applied in: ruby 3.1.3-r0</title>
    <updated>2026-10-04T19:13:13.678559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby</p>
<p>Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-jl84667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258775</id>
    <title>EUVD-2026-258775</title>
    <updated>2026-10-04T19:13:13.678578+00:00</updated>
    <content>EUVD-2026-258775</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33621</id>
    <title>fkie_cve-2021-33621</title>
    <updated>2026-10-04T19:13:13.678589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-33621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vc47-6rqg-c7f5</id>
    <title>GHSA-vc47-6rqg-c7f5 — HTTP response splitting in CGI</title>
    <updated>2026-10-04T19:13:13.678610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: cgi</p>
<p>Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vc47-6rqg-c7f5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-33621</id>
    <title>gsd-2021-33621</title>
    <updated>2026-10-04T19:13:13.678631+00:00</updated>
    <content>gsd-2021-33621</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-33621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1003</id>
    <title>OESA-2023-1003 — ruby security update</title>
    <updated>2026-10-04T19:13:13.678641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ruby, openEuler:20.03-LTS-SP3: ruby, openEuler:22.03-LTS: ruby, openEuler:22.03-LTS-SP1: ruby</p>
<p>Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).


Security Fix(es):

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.(CVE-2021-33621)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12539-1</id>
    <title>openSUSE-SU-2024:12539-1 — libruby3_1-3_1-3.1.3-1.1 on GA media</title>
    <updated>2026-10-04T19:13:13.678667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libruby3_1-3_1-3.1.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12539-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:3291</id>
    <title>RHSA-2023:3291 — Red Hat Security Advisory: rh-ruby27-ruby security, bug fix, and enhancement update</title>
    <updated>2026-10-04T19:13:13.678684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby/cgi-gem: HTTP response splitting in CGI ruby: ReDoS vulnerability in URI ruby: ReDoS vulnerability in Time</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:3291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33621</id>
    <title>UBUNTU-CVE-2021-33621</title>
    <updated>2026-10-04T19:13:13.678701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:25.10: jruby and 1 more</p>
<p>The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2173</id>
    <title>WID-SEC-W-2022-2173 — Ruby: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-04T19:13:13.678730+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2173"/>
  </entry>
</feed>
