目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Ruby 厂商漏洞列表 / CVE 中文分析 33

Ruby 厂商相关 33 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Ruby 是一种动态、面向对象的编程语言,广泛用于 Web 开发及自动化脚本编写。其生态中常见漏洞包括远程代码执行、跨站脚本及逻辑越权,多源于依赖库缺陷或输入验证不足。值得关注的是,Ruby 核心团队定期发布安全补丁以修复高危风险,开发者需及时更新版本并遵循安全编码规范,以防范已知 CVE 带来的潜在威胁。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-71847 Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams — jsonCWE-416 8.7 High2026-08-07
CVE-2026-54696 Ruby JSON: JSON generator heap buffer overflow when streaming to an IO — jsonCWE-122 3.7 Low2026-06-30
CVE-2026-47242 Net::IMAP: Command Injection via ID command argument — net-imapCWE-77--2026-06-22
CVE-2026-47240 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — net-imapCWE-77--2026-06-22
CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation — net-imapCWE-162--2026-06-22
CVE-2026-42258 net-imap: Command Injection via unvalidated Symbol inputs — net-imapCWE-77 5.8 Medium2026-05-09
CVE-2026-42257 net-imap: Command Injection via "raw" arguments to multiple commands — net-imapCWE-93 6.5 -2026-05-09
CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication — net-imapCWE-1322 6.5 -2026-05-09
CVE-2026-42245 net-imap: Quadratic complexity when reading response literals — net-imapCWE-407 7.5 -2026-05-09
CVE-2026-42246 net-imap vulnerable to STARTTLS stripping via invalid response timing — net-imapCWE-392 7.6 High2026-05-09
CVE-2026-41316 ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — erbCWE-693 8.1 High2026-04-24
CVE-2026-27820 zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption — zlibCWE-120 9.8 -2026-04-16
CVE-2026-33210 Ruby JSON has a format string injection vulnerability — jsonCWE-134 8.2 -2026-03-20
CVE-2025-61594 URI Credential Leakage Bypass over CVE-2025-27221 — uriCWE-200 7.5 -2025-12-30
CVE-2025-58767 REXML has a DoS condition when parsing malformed XML file — rexmlCWE-400 7.5AIHighAI2025-09-17
CVE-2025-24294 Ruby 安全漏洞 — resolv 7.5AIHighAI2025-07-12
CVE-2025-6442 Ruby WEBrick read_header HTTP Request Smuggling Vulnerability — WEBrickCWE-444 5.9AIMediumAI2025-06-25
CVE-2025-43857 net-imap rubygem vulnerable to possible DoS by memory exhaustion — net-imapCWE-400 7.5AIHighAI2025-04-28
CVE-2025-27788 Ruby JSON Parser has Out-of-bounds Read — jsonCWE-125 7.5 High2025-03-12
CVE-2025-25186 Net::IMAP vulnerable to possible DoS by memory exhaustion — net-imapCWE-400 6.5 Medium2025-02-10
CVE-2024-49761 REXML ReDoS vulnerability — rexmlCWE-1333 7.5 -2024-10-28
CVE-2024-43398 REXML denial of service vulnerability — rexmlCWE-776 5.9 Medium2024-08-22
CVE-2024-41946 REXML DoS vulnerability — rexmlCWE-400 5.3 Medium2024-08-01
CVE-2024-41123 REXML DoS vulnerability — rexmlCWE-400 5.3 Medium2024-08-01
CVE-2024-39908 Denial of service in REXML — rexmlCWE-400 4.3 Medium2024-07-16
CVE-2024-35176 REXML contains a denial of service vulnerability — rexmlCWE-400 5.3 Medium2024-05-16
CVE-2015-1855 Ruby OpenSSL extension 输入验证错误漏洞 — Ruby 5.9 -2019-11-29
CVE-2011-3624 Ruby 注入漏洞 — Ruby 5.3 -2019-11-26
CVE-2013-6461 Nokogiri 安全漏洞 — Nokogiri gem 6.5 -2019-11-05
CVE-2013-6460 Nokogiri 安全漏洞 — Nokogiri gem 7.5 -2019-11-05

本页汇总了 Ruby 厂商截至目前公开的全部 33 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。