<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:48:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:3020 — Important: ruby:2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:3020</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc and 21 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source (CVE-2020-36327)&lt;/p&gt;
&lt;p&gt;* rubygem-rdoc: Command injection vulnerability in RDoc (CVE-2021-31799)&lt;/p&gt;
&lt;p&gt;* ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host (CVE-2021-31810)&lt;/p&gt;
&lt;p&gt;* ruby: StartTLS stripping vulnerability in Net::IMAP (CVE-2021-32066)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc and 21 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source (CVE-2020-36327)&lt;/p&gt;
&lt;p&gt;* rubygem-rdoc: Command injection vulnerability in RDoc (CVE-2021-31799)&lt;/p&gt;
&lt;p&gt;* ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host (CVE-2021-31810)&lt;/p&gt;
&lt;p&gt;* ruby: StartTLS stripping vulnerability in Net::IMAP (CVE-2021-32066)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:3020</guid>
    </item>
    <item>
      <title>bdu:2021-05398</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05398</link>
      <description>bdu:2021-05398</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05398</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-31799 — CVE-2021-31799 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-31799</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-31799</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-ZN97904 — Security fix for CVE-2021-31799 applied in: ruby 2.7.4-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-zn97904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-zn97904</guid>
    </item>
    <item>
      <title>EUVD-2026-195926</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-195926</link>
      <description>EUVD-2026-195926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-195926</guid>
    </item>
    <item>
      <title>fkie_cve-2021-31799</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-31799</link>
      <description>&lt;p&gt;In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-31799</guid>
    </item>
    <item>
      <title>GHSA-ggxm-pgc9-g7fp — Arbitrary Code Execution in Rdoc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ggxm-pgc9-g7fp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rdoc&lt;/p&gt;
&lt;p&gt;In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rdoc&lt;/p&gt;
&lt;p&gt;In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ggxm-pgc9-g7fp</guid>
    </item>
    <item>
      <title>gsd-2021-31799</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-31799</link>
      <description>gsd-2021-31799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-31799</guid>
    </item>
    <item>
      <title>OESA-2021-1306 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ruby, openEuler:20.03-LTS-SP2: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&#13;
&#13;
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.(CVE-2021-31799)&#13;
&#13;
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).(CVE-2021-31810)&#13;
&#13;
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a &amp;amp;quot;StartTLS stripping attack.&amp;amp;quot;(CVE-2021-32066)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ruby, openEuler:20.03-LTS-SP2: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&#13;
&#13;
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.(CVE-2021-31799)&#13;
&#13;
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).(CVE-2021-31810)&#13;
&#13;
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a &amp;amp;quot;StartTLS stripping attack.&amp;amp;quot;(CVE-2021-32066)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1306</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1535-1 — Security update for ruby2.5</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1535-1</link>
      <description>&lt;p&gt;Security update for ruby2.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby2.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1535-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3559 — Red Hat Security Advisory: rh-ruby27-ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3559</link>
      <description>&lt;p&gt;rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source rubygem-rdoc: Command injection vulnerability in RDoc ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host ruby: StartTLS stripping vulnerability in Net::IMAP&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source rubygem-rdoc: Command injection vulnerability in RDoc ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host ruby: StartTLS stripping vulnerability in Net::IMAP&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3559</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3837-1 — Security update for ruby2.1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3837-1</link>
      <description>&lt;p&gt;Security update for ruby2.1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby2.1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3837-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-31799</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31799</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:20.04:LTS: ruby2.7&lt;/p&gt;
&lt;p&gt;In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:20.04:LTS: ruby2.7&lt;/p&gt;
&lt;p&gt;In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31799</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2461 — Ruby: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2461</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2461</guid>
    </item>
  </channel>
</rss>
