<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:06:40.510605+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:3500</id>
    <title>ALSA-2024:3500 — Moderate: ruby:3.0 security update</title>
    <updated>2026-10-03T08:06:40.646778+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler, AlmaLinux:8: rubygem-io-console and 18 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)
* ruby: RCE vulnerability with .rdoc_options in RDoc (CVE-2024-27281)
* ruby: Buffer overread vulnerability in StringIO (CVE-2024-27280)
* ruby: Arbitrary memory address read vulnerability with Regex search (CVE-2024-27282)</p>
<p>For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:3500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-03599</id>
    <title>bdu:2024-03599</title>
    <updated>2026-10-03T08:06:40.646915+00:00</updated>
    <content>bdu:2024-03599</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-03599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-27282</id>
    <title>BELL-CVE-2024-27282</title>
    <updated>2026-10-03T08:06:40.646934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: ruby, Alpaquita:stream: ruby</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-27282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-ruby-2024-27282</id>
    <title>BIT-ruby-2024-27282</title>
    <updated>2026-10-03T08:06:40.646955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: ruby</p>
<p>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-ruby-2024-27282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0055</id>
    <title>certfr-2025-avi-0055 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un…</title>
    <updated>2026-10-03T08:06:40.646974+00:00</updated>
    <content>certfr-2025-avi-0055</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-la33786</id>
    <title>CLEANSTART-2026-LA33786 — Security fix for CVE-2024-27282 applied in: ruby 3.3.1-r0</title>
    <updated>2026-10-03T08:06:40.646991+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby</p>
<p>Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-la33786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259032</id>
    <title>EUVD-2026-259032</title>
    <updated>2026-10-03T08:06:40.647009+00:00</updated>
    <content>EUVD-2026-259032</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27282</id>
    <title>fkie_cve-2024-27282</title>
    <updated>2026-10-03T08:06:40.647020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-27282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-63cq-cj6g-qfr2</id>
    <title>GHSA-63cq-cj6g-qfr2</title>
    <updated>2026-10-03T08:06:40.647040+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-63cq-cj6g-qfr2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-27282</id>
    <title>gsd-2024-27282</title>
    <updated>2026-10-03T08:06:40.647054+00:00</updated>
    <content>gsd-2024-27282</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-27282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-27282</id>
    <title>msrc_CVE-2024-27282 — An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler it…</title>
    <updated>2026-10-03T08:06:40.647064+00:00</updated>
    <content>msrc_CVE-2024-27282</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-27282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1545</id>
    <title>OESA-2024-1545 — ruby security update</title>
    <updated>2026-10-03T08:06:40.647080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ruby</p>
<p>Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).

Security Fix(es):

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.(CVE-2024-27282)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3500</id>
    <title>RHSA-2024:3500 — Red Hat Security Advisory: ruby:3.0 security update</title>
    <updated>2026-10-03T08:06:40.647100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby/cgi-gem: HTTP response splitting in CGI ruby: ReDoS vulnerability in URI ruby: ReDoS vulnerability in Time ruby: Buffer overread vulnerability in StringIO ruby: RCE vulnerability with .rdoc_options in RDoc ruby: Arbitrary memory address read vulnerability with Regex search</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7305</id>
    <title>RHSA-2026:7305 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T08:06:40.647121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: WEBrick CGI source disclosure ruby: Integer overflows in rb_str_buf_append() ruby: Integer overflows in rb_ary_store() ruby: Unsafe use of alloca in rb_str_format() ruby: integer overflow in rb_ary_splice/update/replace() - REALLOC_N ruby: integer overflow in rb_ary_splice/update/replace() - beg + rlen ruby: multiple insufficient safe mode restrictions ruby: WEBrick DoS vulnerability (CPU consumption) ruby: missing "taintness" checks in dl module ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module ruby: dlopen could open a library with tainted library name ruby: memory corruption in BigDecimal on 64bit platforms ruby: Properly initialize the random number generator when forking new process ruby: Properly initialize the random number generator when forking new process ruby: Properly initialize the random number generator when forking new process ruby: hash table collisions CPU usage DoS (oCERT-2011-003) ruby: Murmur hash-flooding DoS flaw in ruby 1.9 (oCERT-2012-001) ruby: entity expansion DoS vulnerability in REXML ruby: off-by-one stack-based buffer overflow in the encodes() function ruby: Unsafe parsing of long strings via decode_www_form_component method ruby: REXML billion laughs attack via parameter entity expansion ruby: REXML incomplete fix for CVE-2014-8080 ruby: dlopen could open a library with tainted library name ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP ruby: Es…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27282</id>
    <title>UBUNTU-CVE-2024-27282</title>
    <updated>2026-10-03T08:06:40.647187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:24.04:LTS: ruby3.2 and 2 more</p>
<p>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0952</id>
    <title>WID-SEC-W-2024-0952 — Ruby: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T08:06:40.647231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Ruby ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0952"/>
  </entry>
</feed>
