Skip to content

Commit 87eb657

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@94dccfd
1 parent ca9b25c commit 87eb657

2 files changed

Lines changed: 75 additions & 0 deletions

File tree

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-67987 (ruby_llm): Polynomial-Time Regular Expression Denial of Service
4+
(ReDoS) vulnerability'
5+
comments: false
6+
categories:
7+
- ruby_llm
8+
advisory:
9+
gem: ruby_llm
10+
cve: 2026-67987
11+
ghsa: 5m38-526f-3498
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-67987
13+
title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
14+
date: 2026-10-01
15+
description: |-
16+
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
17+
contains polynomial-time regular expression denial-of-service
18+
conditions in think-tag response parsing on Ruby 3.1.x.
19+
A malicious or anomalous model response containing many unterminated
20+
tags can cause excessive CPU consumption in two consecutive
21+
regular expressions and delay chat-completion processing.
22+
cvss_v3: 7.5
23+
unaffected_versions:
24+
- "< 0.1.0.pre42"
25+
patched_versions:
26+
- ">= 2.0.0.rc1"
27+
related:
28+
url:
29+
- https://nvd.nist.gov/vuln/detail/CVE-2026-67987
30+
- https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
31+
- https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
32+
- https://github.com/crmne/ruby_llm/commit/5e88411f171721b381853fa77d254e266dcf6ad8
33+
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/protocols/chat_completions/chat.rb#L355-L356
34+
- https://github.com/advisories/GHSA-5m38-526f-3498
35+
notes: |
36+
- cvss_v3 from nvd.nist.gov and GHSA URL
37+
- /commit/ URL mentioend this CVE number and patch version.
38+
- Unreviewed GHSA advisory
39+
---
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-67989 (ruby_llm): Polynomial-Time Regular Expression Denial of Service
4+
(ReDoS) vulnerability'
5+
comments: false
6+
categories:
7+
- ruby_llm
8+
advisory:
9+
gem: ruby_llm
10+
cve: 2026-67989
11+
ghsa: 57hg-jgw4-wcqw
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-67989
13+
title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
14+
date: 2026-10-01
15+
description: |-
16+
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
17+
contains a polynomial-time regular expression denial-of-service
18+
condition in Mistral model capability matching on Ruby 3.1.x.
19+
cvss_v3: 7.5
20+
unaffected_versions:
21+
- "< 0.1.0.pre42"
22+
patched_versions:
23+
- ">= 2.0.0.rc1"
24+
related:
25+
url:
26+
- https://nvd.nist.gov/vuln/detail/CVE-2026-67989
27+
- https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
28+
- https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
29+
- https://github.com/crmne/ruby_llm/commit/dd3c84812598def03d4aff77b5447c41d8f5c34e
30+
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/providers/mistral/capabilities.rb#L92
31+
- https://github.com/advisories/GHSA-57hg-jgw4-wcqw
32+
notes: |
33+
- cvss_v3 from nvd.nist.gov and GHSA URL
34+
- /commit/ URL mentioend this CVE number and patch version.
35+
- Unreviewed GHSA advisory
36+
---

0 commit comments

Comments
 (0)