Ruby is a widely embedded interpreted programming language whose vulnerability footprint, despite a focused product portfolio, extends to a vast downstream ecosystem of applications and web services that depend on its standard library and runtime. The vendor's disclosures center on its core language implementation, parser libraries such as REXML, and standard library modules including networking (Net), CGI handling, and the built-in WEBrick application server, which collectively form the foundation for dynamic web applications and scripting workloads. Because Ruby sits deep in the software supply chain, individual vulnerabilities in the language or its standard library can propagate across thousands of dependent projects and services, making even modestly scoped flaws consequential to defenders tracking downstream exposure. Defenders should monitor this vendor's releases for their supply-chain reach rather than their volume alone and prioritize understanding which standard library modules are in active use within their Ruby applications; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ruby Lang over time
Signals from CVEs in this vendor scope (137 CVEs).
137 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17405HIGH Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the loca | Dec 15, 2017 | 8.8 | 78 | NO | YES |
CVE-2008-3656HIGH Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through | Aug 13, 2008 | 7.8 | 75 | NO | YES |
CVE-2021-28966HIGH In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. | Jul 30, 2021 | 7.5 | 56 | NO | NO |
CVE-2013-4164MEDIUM Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers | Nov 23, 2013 | 6.8 | 44 | NO | YES |
CVE-2013-0233MEDIUM Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when | Apr 25, 2013 | 6.8 | 39 | NO | YES |
CVE-2009-4492HIGH WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing | Jan 13, 2010 | 7.5 | 39 | NO | YES |
CVE-2008-4310HIGH httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted H | Dec 9, 2008 | 7.8 | 39 | NO | YES |
CVE-2026-42257CRITICAL Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw stri | May 9, 2026 | 9.8 | 37 | NO | NO |
CVE-2018-16395CRITICAL An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects a | Nov 16, 2018 | 9.8 | 36 | NO | NO |
CVE-2026-33210CRITICAL Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of se | Mar 20, 2026 | 9.1 | 35 | NO | NO |
Signals from CVEs in this vendor scope (137 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ruby Lang.
Media articles that mention a CVE ID that affects a product developed by Ruby Lang — matched by CVE ID, not by vendor name.