<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:12:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:3821 — Moderate: ruby:2.7 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:3821</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc and 21 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: ruby (2.7). (BZ#2189465)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc and 21 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: ruby (2.7). (BZ#2189465)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:3821</guid>
    </item>
    <item>
      <title>bdu:2023-03834</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03834</link>
      <description>bdu:2023-03834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03834</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-33621 — CVE-2021-33621 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-33621</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-33621</guid>
    </item>
    <item>
      <title>BIT-ruby-2021-33621</title>
      <link>https://cve.radiocsirt.org/vuln/bit-ruby-2021-33621</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: ruby&lt;/p&gt;
&lt;p&gt;The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: ruby&lt;/p&gt;
&lt;p&gt;The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-ruby-2021-33621</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0318 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;VMware&lt;/span&gt;. Elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0318</link>
      <description>certfr-2023-avi-0318</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0318</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-JL84667 — Security fix for CVE-2021-33621 applied in: ruby 3.1.3-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-jl84667</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-jl84667</guid>
    </item>
    <item>
      <title>EUVD-2026-258775</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258775</link>
      <description>EUVD-2026-258775</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258775</guid>
    </item>
    <item>
      <title>fkie_cve-2021-33621</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33621</link>
      <description>&lt;p&gt;The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-33621</guid>
    </item>
    <item>
      <title>GHSA-vc47-6rqg-c7f5 — HTTP response splitting in CGI</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vc47-6rqg-c7f5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: cgi&lt;/p&gt;
&lt;p&gt;Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: cgi&lt;/p&gt;
&lt;p&gt;Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vc47-6rqg-c7f5</guid>
    </item>
    <item>
      <title>gsd-2021-33621</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-33621</link>
      <description>gsd-2021-33621</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-33621</guid>
    </item>
    <item>
      <title>OESA-2023-1003 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ruby, openEuler:20.03-LTS-SP3: ruby, openEuler:22.03-LTS: ruby, openEuler:22.03-LTS-SP1: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).
&#13;
&#13;
Security Fix(es):&#13;
&#13;
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.(CVE-2021-33621)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ruby, openEuler:20.03-LTS-SP3: ruby, openEuler:22.03-LTS: ruby, openEuler:22.03-LTS-SP1: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).
&#13;
&#13;
Security Fix(es):&#13;
&#13;
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.(CVE-2021-33621)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1003</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12539-1 — libruby3_1-3_1-3.1.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12539-1</link>
      <description>&lt;p&gt;libruby3_1-3_1-3.1.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libruby3_1-3_1-3.1.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12539-1</guid>
    </item>
    <item>
      <title>RHSA-2023:3291 — Red Hat Security Advisory: rh-ruby27-ruby security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3291</link>
      <description>&lt;p&gt;ruby/cgi-gem: HTTP response splitting in CGI ruby: ReDoS vulnerability in URI ruby: ReDoS vulnerability in Time&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby/cgi-gem: HTTP response splitting in CGI ruby: ReDoS vulnerability in URI ruby: ReDoS vulnerability in Time&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3291</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-33621</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33621</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:25.10: jruby and 1 more&lt;/p&gt;
&lt;p&gt;The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:25.10: jruby and 1 more&lt;/p&gt;
&lt;p&gt;The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33621</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2173 — Ruby: Schwachstelle ermöglicht Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2173</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2173</guid>
    </item>
  </channel>
</rss>
