File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ ---
2+ layout : advisory
3+ title : ' CVE-2026-67987 (ruby_llm): Polynomial-Time Regular Expression Denial of Service
4+ (ReDoS) vulnerability'
5+ comments : false
6+ categories :
7+ - ruby_llm
8+ advisory :
9+ gem : ruby_llm
10+ cve : 2026-67987
11+ ghsa : 5m38-526f-3498
12+ url : https://nvd.nist.gov/vuln/detail/CVE-2026-67987
13+ title : Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
14+ date : 2026-10-01
15+ description : |-
16+ crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
17+ contains polynomial-time regular expression denial-of-service
18+ conditions in think-tag response parsing on Ruby 3.1.x.
19+ A malicious or anomalous model response containing many unterminated
20+ tags can cause excessive CPU consumption in two consecutive
21+ regular expressions and delay chat-completion processing.
22+ cvss_v3 : 7.5
23+ unaffected_versions :
24+ - " < 0.1.0.pre42"
25+ patched_versions :
26+ - " >= 2.0.0.rc1"
27+ related :
28+ url :
29+ - https://nvd.nist.gov/vuln/detail/CVE-2026-67987
30+ - https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
31+ - https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
32+ - https://github.com/crmne/ruby_llm/commit/5e88411f171721b381853fa77d254e266dcf6ad8
33+ - https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/protocols/chat_completions/chat.rb#L355-L356
34+ - https://github.com/advisories/GHSA-5m38-526f-3498
35+ notes : |
36+ - cvss_v3 from nvd.nist.gov and GHSA URL
37+ - /commit/ URL mentioend this CVE number and patch version.
38+ - Unreviewed GHSA advisory
39+ ---
Original file line number Diff line number Diff line change 1+ ---
2+ layout : advisory
3+ title : ' CVE-2026-67989 (ruby_llm): Polynomial-Time Regular Expression Denial of Service
4+ (ReDoS) vulnerability'
5+ comments : false
6+ categories :
7+ - ruby_llm
8+ advisory :
9+ gem : ruby_llm
10+ cve : 2026-67989
11+ ghsa : 57hg-jgw4-wcqw
12+ url : https://nvd.nist.gov/vuln/detail/CVE-2026-67989
13+ title : Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
14+ date : 2026-10-01
15+ description : |-
16+ crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
17+ contains a polynomial-time regular expression denial-of-service
18+ condition in Mistral model capability matching on Ruby 3.1.x.
19+ cvss_v3 : 7.5
20+ unaffected_versions :
21+ - " < 0.1.0.pre42"
22+ patched_versions :
23+ - " >= 2.0.0.rc1"
24+ related :
25+ url :
26+ - https://nvd.nist.gov/vuln/detail/CVE-2026-67989
27+ - https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
28+ - https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
29+ - https://github.com/crmne/ruby_llm/commit/dd3c84812598def03d4aff77b5447c41d8f5c34e
30+ - https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/providers/mistral/capabilities.rb#L92
31+ - https://github.com/advisories/GHSA-57hg-jgw4-wcqw
32+ notes : |
33+ - cvss_v3 from nvd.nist.gov and GHSA URL
34+ - /commit/ URL mentioend this CVE number and patch version.
35+ - Unreviewed GHSA advisory
36+ ---
You can’t perform that action at this time.
0 commit comments