From 24567c75d8705d81d3713a8c72676721d4ca6ceb Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Sat, 3 Oct 2026 12:15:34 -0400 Subject: [PATCH] Two new ruby_llm advisories --- gems/ruby_llm/CVE-2026-67987.yml | 31 +++++++++++++++++++++++++++++++ gems/ruby_llm/CVE-2026-67989.yml | 28 ++++++++++++++++++++++++++++ 2 files changed, 59 insertions(+) create mode 100644 gems/ruby_llm/CVE-2026-67987.yml create mode 100644 gems/ruby_llm/CVE-2026-67989.yml diff --git a/gems/ruby_llm/CVE-2026-67987.yml b/gems/ruby_llm/CVE-2026-67987.yml new file mode 100644 index 0000000000..5ac9454be9 --- /dev/null +++ b/gems/ruby_llm/CVE-2026-67987.yml @@ -0,0 +1,31 @@ +--- +gem: ruby_llm +cve: 2026-67987 +ghsa: 5m38-526f-3498 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-67987 +title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability +date: 2026-10-01 +description: | + crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 + contains polynomial-time regular expression denial-of-service + conditions in think-tag response parsing on Ruby 3.1.x. + A malicious or anomalous model response containing many unterminated + tags can cause excessive CPU consumption in two consecutive + regular expressions and delay chat-completion processing. +cvss_v3: 7.5 +unaffected_versions: + - "< 0.1.0.pre42" +patched_versions: + - ">= 2.0.0.rc1" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-67987 + - https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1 + - https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1 + - https://github.com/crmne/ruby_llm/commit/5e88411f171721b381853fa77d254e266dcf6ad8 + - https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/protocols/chat_completions/chat.rb#L355-L356 + - https://github.com/advisories/GHSA-5m38-526f-3498 +notes: | + - cvss_v3 from nvd.nist.gov and GHSA URL + - /commit/ URL mentioend this CVE number and patch version. + - Unreviewed GHSA advisory diff --git a/gems/ruby_llm/CVE-2026-67989.yml b/gems/ruby_llm/CVE-2026-67989.yml new file mode 100644 index 0000000000..010bbf998a --- /dev/null +++ b/gems/ruby_llm/CVE-2026-67989.yml @@ -0,0 +1,28 @@ +--- +gem: ruby_llm +cve: 2026-67989 +ghsa: 57hg-jgw4-wcqw +url: https://nvd.nist.gov/vuln/detail/CVE-2026-67989 +title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability +date: 2026-10-01 +description: | + crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 + contains a polynomial-time regular expression denial-of-service + condition in Mistral model capability matching on Ruby 3.1.x. +cvss_v3: 7.5 +unaffected_versions: + - "< 0.1.0.pre42" +patched_versions: + - ">= 2.0.0.rc1" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-67989 + - https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1 + - https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1 + - https://github.com/crmne/ruby_llm/commit/dd3c84812598def03d4aff77b5447c41d8f5c34e + - https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/providers/mistral/capabilities.rb#L92 + - https://github.com/advisories/GHSA-57hg-jgw4-wcqw +notes: | + - cvss_v3 from nvd.nist.gov and GHSA URL + - /commit/ URL mentioend this CVE number and patch version. + - Unreviewed GHSA advisory