Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions gems/ruby_llm/CVE-2026-67987.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
gem: ruby_llm
cve: 2026-67987
ghsa: 5m38-526f-3498
url: https://nvd.nist.gov/vuln/detail/CVE-2026-67987
title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
date: 2026-10-01
description: |
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
contains polynomial-time regular expression denial-of-service
conditions in think-tag response parsing on Ruby 3.1.x.
A malicious or anomalous model response containing many unterminated
tags can cause excessive CPU consumption in two consecutive
regular expressions and delay chat-completion processing.
cvss_v3: 7.5
unaffected_versions:
- "< 0.1.0.pre42"
patched_versions:
- ">= 2.0.0.rc1"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67987
- https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
- https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
- https://github.com/crmne/ruby_llm/commit/5e88411f171721b381853fa77d254e266dcf6ad8
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/protocols/chat_completions/chat.rb#L355-L356
- https://github.com/advisories/GHSA-5m38-526f-3498
notes: |
- cvss_v3 from nvd.nist.gov and GHSA URL
- /commit/ URL mentioend this CVE number and patch version.
- Unreviewed GHSA advisory
28 changes: 28 additions & 0 deletions gems/ruby_llm/CVE-2026-67989.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
gem: ruby_llm
cve: 2026-67989
ghsa: 57hg-jgw4-wcqw
url: https://nvd.nist.gov/vuln/detail/CVE-2026-67989
title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
date: 2026-10-01
description: |
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
contains a polynomial-time regular expression denial-of-service
condition in Mistral model capability matching on Ruby 3.1.x.
cvss_v3: 7.5
unaffected_versions:
- "< 0.1.0.pre42"
patched_versions:
- ">= 2.0.0.rc1"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67989
- https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
- https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
- https://github.com/crmne/ruby_llm/commit/dd3c84812598def03d4aff77b5447c41d8f5c34e
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/providers/mistral/capabilities.rb#L92
- https://github.com/advisories/GHSA-57hg-jgw4-wcqw
notes: |
- cvss_v3 from nvd.nist.gov and GHSA URL
- /commit/ URL mentioend this CVE number and patch version.
- Unreviewed GHSA advisory
Loading