JRuby is a Java-based implementation of the Ruby language that enables Ruby code execution on the Java Virtual Machine, with a focused product footprint centered on the core runtime and OpenSSL wrapper. Its vulnerability exposure reflects the dual nature of the platform, recurrent issues include improper certificate validation in the SSL/TLS layer, cross-site scripting in web-facing applications, and resource-consumption weaknesses tied to the interpreter's handling of Ruby constructs. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jruby over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4123HIGH The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation. | Dec 12, 2023 | 7.5 | 22 | NO | NO |
CVE-2012-5370MEDIUM JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (C | Nov 28, 2012 | 5.0 | 20 | NO | NO |
CVE-2011-4838MEDIUM JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of serv | Dec 30, 2011 | 5.0 | 20 | NO | NO |
CVE-2010-1330MEDIUM The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attacke | Nov 23, 2012 | 4.3 | 19 | NO | NO |
JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby | May 7, 2025 | 3.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jruby.
Media articles that mention a CVE ID that affects a product developed by Jruby — matched by CVE ID, not by vendor name.