Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-4412

28
FAUCET Score

CVE-2015-4412 is a critical BSON injection vulnerability affecting the bson-ruby gem before version 3.0.4. This flaw allows remote attackers to trigger a denial of service through resource consumption or inject arbitrary data via a specially crafted string within the legal? function. With a CVSS score of 9.8, this vulnerability presents a high risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, its high FAUCET Risk Score indicates its inherent danger.

Impacted Technologies

VendorProductVersion(s)CPE
3.0.3CPE matchmatch criteria
cpe:2.3:a:bson_project:bson:3.0.3:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.66%
Probability of exploitation in next 30 days
EPSS Percentile
90.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0466 is in the 84th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: bsonFixed in: 3.0.4
rubygemspatch availablevia ghsa
Product: bsonFixed in: 1.12.3
redhatno patchvia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: ruby193-rubygem-bson
redhatno patchvia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: rubygem-bson
redhatno patchvia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-ror41-rubygem-bson
redhatno patchvia redhat_api
Product: Red Hat Software CollectionsFixed in: ror40-rubygem-bson
redhatno patchvia redhat_api
Product: Red Hat Software CollectionsFixed in: ruby193-rubygem-bson
redhatno patchvia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: ruby193-rubygem-bson

Vendor Advisories (2)

rubygemsGHSA-h6rj-8r3c-9gpjcritical

bson is vulnerable to denial of service due to incorrect regex validation

Mar 5, 2018
redhatCVE-2015-4412Low

rubygem-bson: data injection vulnerability through a crafted ObjectId

Jun 4, 2015

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / mongodb/bson-ruby/commit/976da329ff03ecdfca3030eb6efe3c85e6db9999
Third Party Advisory
github.com / mongodb/bson-ruby/compare/7446d7c6764dfda8dc4480ce16d5c023e74be5ca...28f34978a85b689a4480b4d343389bf4886522e7
Issue TrackingPatchThird Party Advisory
sakurity.com / blog/2015/06/04/mongo_ruby_regexp.html
ExploitPatchThird Party Advisory
openwall.com / lists/oss-security/2015/06/06/3
Mailing List
securityfocus.com / bid/75045
Third Party AdvisoryVDB Entry