Known vulnerabilities in ruby (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:ruby_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 25
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ruby (Red Hat package) ruby (Red Hat package) is affected by 25 known vulnerabilities: 5 high, 12 medium, 8 low Critical High Medium Low

Vulnerabilities (25)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126644 - Improper Access Control
CVE-2026-41316
CWE-284 High
No
No
3.0.4-160.2.el9_0, 3.0.7-162.el9_4.2, 3.0.7-166.el9_7, 3.3.10-11.el10_0.1 21.04.2026 SB2026042131
SB20260509132
SB2026051815
and 10 more
#VU118253 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-26625
CWE-59 High
No
No
3.3.10-11.el10_0 11.11.2025 SB2025111128
SB2025111129
SB2025111130
and 20 more
#VU116663 - Exposure of sensitive information to an unauthorized actor
CVE-2025-61594
CWE-200 Medium
No
No
3.3.10-11.el10_1 07.10.2025 SB2025100723
SB2025110338
SB2025111485
and 4 more
#VU115794 - Resource exhaustion
CVE-2025-58767
CWE-400 Low
No
No
3.3.10-11.el10_0, 3.3.10-11.el10_1 18.09.2025 SB2025091868
SB2025102434
SB2025110338
and 12 more
#VU114812 - Resource exhaustion
CVE-2025-24294
CWE-400 Medium
No
No
3.3.10-11.el10_0, 3.3.10-11.el10_1 04.09.2025 SB2025090467
SB2025090470
SB2025090473
and 10 more
#VU112026 - Asymmetric Resource Consumption (Amplification)
CVE-2025-25186
CWE-405 Medium
No
No
3.3.8-10.el10_0 27.06.2025 SB2025062740
SB2025062741
SB2025062742
and 7 more
#VU105106 - Improper input validation
CVE-2025-27219
CWE-20 Medium
No
No
3.3.8-10.el10_0 27.02.2025 SB20250227242
SB2025030761
SB2025031451
and 15 more
#VU105105 - Exposure of sensitive information to an unauthorized actor
CVE-2025-27221
CWE-200 Medium
No
No
3.3.8-10.el10_0 27.02.2025 SB20250227241
SB2025030761
SB2025031451
and 16 more
#VU99358 - Inefficient Regular Expression Complexity
CVE-2024-49761
CWE-1333 Medium
No
No
3.0.4-160.1.el9_0, 3.0.4-161.el9_2.2, 3.0.7-162.el9_4.1, 3.0.7-163.el9_5 28.10.2024 SB2024102837
SB2024110504
SB20241108111
and 38 more
#VU69506 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2021-33621
CWE-113 Medium
No
No
3.0.4-161.el9_2.1 22.11.2022 SB2022112239
SB2022112439
SB2023011730
and 31 more
#VU68860 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31163
CWE-22 Medium
No
No
2.4.9-94.el7rhgs 31.10.2022 SB2022103147
SB2022103161
SB2022072942
and 6 more
#VU65835 - Incorrect Regular Expression
CVE-2022-31129
CWE-185 Medium
No
No
2.4.9-94.el7rhgs 27.07.2022 SB2022072729
SB2022072901
SB2022081048
and 102 more
#VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30123
CWE-78 High
No
No
2.4.9-94.el7rhgs 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 14 more
#VU64862 - Improper input validation
CVE-2022-30122
CWE-20 Medium
No
No
2.4.9-94.el7rhgs 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 8 more
#VU62081 - Type conversion
CVE-2022-28739
CWE-704 High
No
No
3.0.4-160.el9_0 12.04.2022 SB2022041215
SB2022041404
SB2022060704
and 28 more
#VU62080 - Double Free
CVE-2022-28738
CWE-415 High
No
No
3.0.4-160.el9_0 12.04.2022 SB2022041215
SB2022041404
SB2022060704
and 13 more
#VU61798 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24790
CWE-444 Medium
No
No
2.4.9-94.el7rhgs 01.04.2022 SB2022040112
SB2022052603
SB2022092241
and 12 more
#VU20192 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8323
CWE-79 Low
No
No
2.0.0.648-37.el7_4 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20191 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8322
CWE-79 Low
No
No
2.0.0.648-37.el7_4 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20189 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8324
CWE-94 Medium
No
No
2.0.0.648-37.el7_4 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 11 more


Showing elements 1 - 20 out of 25