<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:03:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:3500 — Moderate: ruby:3.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:3500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler, AlmaLinux:8: rubygem-io-console and 18 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)
* ruby: RCE vulnerability with .rdoc_options in RDoc (CVE-2024-27281)
* ruby: Buffer overread vulnerability in StringIO (CVE-2024-27280)
* ruby: Arbitrary memory address read vulnerability with Regex search (CVE-2024-27282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler, AlmaLinux:8: rubygem-io-console and 18 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)
* ruby: RCE vulnerability with .rdoc_options in RDoc (CVE-2024-27281)
* ruby: Buffer overread vulnerability in StringIO (CVE-2024-27280)
* ruby: Arbitrary memory address read vulnerability with Regex search (CVE-2024-27282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:3500</guid>
    </item>
    <item>
      <title>bdu:2024-03599</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03599</link>
      <description>bdu:2024-03599</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03599</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-27282</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-27282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: ruby, Alpaquita:stream: ruby&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: ruby, Alpaquita:stream: ruby&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-27282</guid>
    </item>
    <item>
      <title>BIT-ruby-2024-27282</title>
      <link>https://cve.radiocsirt.org/vuln/bit-ruby-2024-27282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: ruby&lt;/p&gt;
&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: ruby&lt;/p&gt;
&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-ruby-2024-27282</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0055 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0055</link>
      <description>certfr-2025-avi-0055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0055</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-LA33786 — Security fix for CVE-2024-27282 applied in: ruby 3.3.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-la33786</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-la33786</guid>
    </item>
    <item>
      <title>EUVD-2026-259032</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259032</link>
      <description>EUVD-2026-259032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259032</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27282</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27282</link>
      <description>&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27282</guid>
    </item>
    <item>
      <title>GHSA-63cq-cj6g-qfr2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-63cq-cj6g-qfr2</link>
      <description>&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-63cq-cj6g-qfr2</guid>
    </item>
    <item>
      <title>gsd-2024-27282</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27282</link>
      <description>gsd-2024-27282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27282</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-27282 — An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler it…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-27282</link>
      <description>msrc_CVE-2024-27282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-27282</guid>
    </item>
    <item>
      <title>OESA-2024-1545 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1545</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.(CVE-2024-27282)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.(CVE-2024-27282)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1545</guid>
    </item>
    <item>
      <title>RHSA-2024:3500 — Red Hat Security Advisory: ruby:3.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3500</link>
      <description>&lt;p&gt;ruby/cgi-gem: HTTP response splitting in CGI ruby: ReDoS vulnerability in URI ruby: ReDoS vulnerability in Time ruby: Buffer overread vulnerability in StringIO ruby: RCE vulnerability with .rdoc_options in RDoc ruby: Arbitrary memory address read vulnerability with Regex search&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby/cgi-gem: HTTP response splitting in CGI ruby: ReDoS vulnerability in URI ruby: ReDoS vulnerability in Time ruby: Buffer overread vulnerability in StringIO ruby: RCE vulnerability with .rdoc_options in RDoc ruby: Arbitrary memory address read vulnerability with Regex search&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3500</guid>
    </item>
    <item>
      <title>RHSA-2026:7305 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7305</link>
      <description>&lt;p&gt;ruby: WEBrick CGI source disclosure ruby: Integer overflows in rb_str_buf_append() ruby: Integer overflows in rb_ary_store() ruby: Unsafe use of alloca in rb_str_format() ruby: integer overflow in rb_ary_splice/update/replace() - REALLOC_N ruby: integer overflow in rb_ary_splice/update/replace() - beg + rlen ruby: multiple insufficient safe mode restrictions ruby: WEBrick DoS vulnerability (CPU consumption) ruby: missing &amp;#34;taintness&amp;#34; checks in dl module ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module ruby: dlopen could open a library with tainted library name ruby: memory corruption in BigDecimal on 64bit platforms ruby: Properly initialize the random number generator when forking new process ruby: Properly initialize the random number generator when forking new process ruby: Properly initialize the random number generator when forking new process ruby: hash table collisions CPU usage DoS (oCERT-2011-003) ruby: Murmur hash-flooding DoS flaw in ruby 1.9 (oCERT-2012-001) ruby: entity expansion DoS vulnerability in REXML ruby: off-by-one stack-based buffer overflow in the encodes() function ruby: Unsafe parsing of long strings via decode_www_form_component method ruby: REXML billion laughs attack via parameter entity expansion ruby: REXML incomplete fix for CVE-2014-8080 ruby: dlopen could open a library with tainted library name ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP ruby: Es…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby: WEBrick CGI source disclosure ruby: Integer overflows in rb_str_buf_append() ruby: Integer overflows in rb_ary_store() ruby: Unsafe use of alloca in rb_str_format() ruby: integer overflow in rb_ary_splice/update/replace() - REALLOC_N ruby: integer overflow in rb_ary_splice/update/replace() - beg + rlen ruby: multiple insufficient safe mode restrictions ruby: WEBrick DoS vulnerability (CPU consumption) ruby: missing &amp;#34;taintness&amp;#34; checks in dl module ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module ruby: dlopen could open a library with tainted library name ruby: memory corruption in BigDecimal on 64bit platforms ruby: Properly initialize the random number generator when forking new process ruby: Properly initialize the random number generator when forking new process ruby: Properly initialize the random number generator when forking new process ruby: hash table collisions CPU usage DoS (oCERT-2011-003) ruby: Murmur hash-flooding DoS flaw in ruby 1.9 (oCERT-2012-001) ruby: entity expansion DoS vulnerability in REXML ruby: off-by-one stack-based buffer overflow in the encodes() function ruby: Unsafe parsing of long strings via decode_www_form_component method ruby: REXML billion laughs attack via parameter entity expansion ruby: REXML incomplete fix for CVE-2014-8080 ruby: dlopen could open a library with tainted library name ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP ruby: Es…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7305</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-27282</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:24.04:LTS: ruby3.2 and 2 more&lt;/p&gt;
&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:24.04:LTS: ruby3.2 and 2 more&lt;/p&gt;
&lt;p&gt;An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27282</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0952 — Ruby: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0952</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ruby ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ruby ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0952</guid>
    </item>
  </channel>
</rss>
