Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ruby Lang

First CVE: Oct 1, 2007Active for: 19 yearsTotal CVEs: 266

Ruby is a widely embedded interpreted programming language whose vulnerability footprint, despite a focused product portfolio, extends to a vast downstream ecosystem of applications and web services that depend on its standard library and runtime. The vendor's disclosures center on its core language implementation, parser libraries such as REXML, and standard library modules including networking (Net), CGI handling, and the built-in WEBrick application server, which collectively form the foundation for dynamic web applications and scripting workloads. Because Ruby sits deep in the software supply chain, individual vulnerabilities in the language or its standard library can propagate across thousands of dependent projects and services, making even modestly scoped flaws consequential to defenders tracking downstream exposure. Defenders should monitor this vendor's releases for their supply-chain reach rather than their volume alone and prioritize understanding which standard library modules are in active use within their Ruby applications; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
137
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ruby Lang over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2007
18 years ago
Most Recent CVE
May 22, 2026
63 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (137 CVEs).

137 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-17405HIGH
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the loca
Dec 15, 20178.878NOYES
CVE-2008-3656HIGH
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through
Aug 13, 20087.875NOYES
CVE-2021-28966HIGH
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
Jul 30, 20217.556NONO
CVE-2013-4164MEDIUM
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers
Nov 23, 20136.844NOYES
CVE-2013-0233MEDIUM
Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when
Apr 25, 20136.839NOYES
CVE-2009-4492HIGH
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing
Jan 13, 20107.539NOYES
CVE-2008-4310HIGH
httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted H
Dec 9, 20087.839NOYES
CVE-2026-42257CRITICAL
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw stri
May 9, 20269.837NONO
CVE-2018-16395CRITICAL
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects a
Nov 16, 20189.836NONO
CVE-2026-33210CRITICAL
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of se
Mar 20, 20269.135NONO
View all 137 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products137 CVEs
44%
43%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (4.4%)
Network74 (54.0%)
Unknown57 (41.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low69 (50.4%)
High11 (8.0%)
Unknown57 (41.6%)
User Interaction
None73 (53.3%)
Unknown57 (41.6%)
Required7 (5.1%)
Privileges Required
Low5 (3.6%)
High1 (0.7%)
None74 (54.0%)
Unknown57 (41.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (137 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
2.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
7.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ruby Lang.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ruby Lang — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ruby Lang's Products

View all 7 CNAs →

Top CWEs