CVE-2008-3656 is an algorithmic complexity vulnerability in the WEBrick component of Ruby versions 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423. An unauthenticated attacker can exploit this via a crafted HTTP request, leading to a denial of service (CPU consumption) due to a backtracking regular expression. With a CVSS score of 7.8 and an EPSS score indicating high exploitability, this vulnerability is considered severe. While not on the KEV catalog, public exploit modules exist for Metasploit and ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.5CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
1.6.8CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.6.8:*:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:* | ||
1.8.1CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.1:*:*:*:*:*:*:* | ||
1.8.1CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.1:-9:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.