CVE Tools

Ruby

4 CVEs tracked since 2019. Since Nov 2019, none of them reached CISA KEV.

Ruby CVEs per month

Nov 2019 to Nov 2019. Point at a month, or focus the strip and use the arrow keys.
Ruby CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-1140

Products

The products that kept showing up in Ruby's monthly top three, with their CVEs summed over those months.

  1. Nokogiri Gem21 month
  2. Ruby21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ruby.

  1. CVE-2026-80213An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octet...4.0
  2. CVE-2026-80212An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new cla...7.5
  3. CVE-2026-71847Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams—
  4. CVE-2026-54696Ruby JSON: JSON generator heap buffer overflow when streaming to an IO3.7
  5. CVE-2026-47242Net::IMAP: Command Injection via ID command argument—
  6. CVE-2026-47240Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument—
  7. CVE-2026-47241Net::IMAP: Denial of Service via incomplete raw argument validation—
  8. CVE-2026-42258net-imap: Command Injection via unvalidated Symbol inputs5.3
  9. CVE-2026-42257net-imap: Command Injection via "raw" arguments to multiple commands9.8
  10. CVE-2026-42256net-imap: Denial of service via high iteration count for `SCRAM-*` authentication6.5
  11. CVE-2026-42245net-imap: Quadratic complexity when reading response literals7.5
  12. CVE-2026-42246net-imap vulnerable to STARTTLS stripping via invalid response timing7.4
  13. CVE-2026-41316ERB has an @_init deserialization guard bypass via def_module / def_method / def_class8.1
  14. CVE-2026-27820zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption9.8
  15. CVE-2026-33210Ruby JSON has a format string injection vulnerability9.1

The record

Peak rank
#101 in Nov 2019
Busiest month shown
Nov 2019, 4 CVEs
Months with a KEV entry
0 since Nov 2019
Monthly snapshots
1 since 2019
Ruby's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store