Ruby
Vendor:
First CVE: Oct 1, 2007 · Active for 18 years
112
Total CVEs
More Total CVEs than 99% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ruby over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2007
18 years ago
Most Recent CVE
May 22, 2026
64 days ago
CVE Severity & Scoring
Ruby112 CVEs
42%
46%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (2.7%)
Network52 (46.4%)
Unknown57 (50.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low48 (42.9%)
High7 (6.3%)
Unknown57 (50.9%)
User Interaction
None51 (45.5%)
Unknown57 (50.9%)
Required4 (3.6%)
Privileges Required
Low3 (2.7%)
High0 (0.0%)
None52 (46.4%)
Unknown57 (50.9%)
Top CVEs
Signals from CVEs in this product scope (112 CVEs).
112 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17405HIGH Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the loca | Dec 15, 2017 | 8.8 | 78 | NO | YES |
CVE-2008-3656HIGH Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through | Aug 13, 2008 | 7.8 | 75 | NO | YES |
CVE-2021-28966HIGH In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. | Jul 30, 2021 | 7.5 | 56 | NO | NO |
CVE-2013-4164MEDIUM Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers | Nov 23, 2013 | 6.8 | 44 | NO | YES |
CVE-2013-0233MEDIUM Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when | Apr 25, 2013 | 6.8 | 39 | NO | YES |
CVE-2009-4492HIGH WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing | Jan 13, 2010 | 7.5 | 39 | NO | YES |
CVE-2008-4310HIGH httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted H | Dec 9, 2008 | 7.8 | 39 | NO | YES |
CVE-2018-16395CRITICAL An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects a | Nov 16, 2018 | 9.8 | 36 | NO | NO |
CVE-2017-14064CRITICAL Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/ | Aug 31, 2017 | 9.8 | 35 | NO | NO |
CVE-2008-1145MEDIUM Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separato | Mar 4, 2008 | 5.0 | 35 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (112 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
2.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
8.9% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (112 CVEs).
Media Mentions
Signals from CVEs in this product scope (112 CVEs).
Top CNAs Publishing CVEs For Ruby
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.7.0 | 2 | 6.4 | 2.6% | 0 | 0 |
| 2.6.0 | 8 | 8.0 | 8.3% | 0 | 0 |
| 2.5.0 | 2 | 9.3 | 39.9% | 0 | 1 |
| 2.4.1 | 5 | 9.0 | 9.0% | 0 | 0 |
| 2.4.0 | 5 | 8.7 | 10.7% | 0 | 0 |
| 2.3.4 | 4 | 8.8 | 10.8% | 0 | 0 |
| 2.3.3 | 4 | 8.8 | 10.8% | 0 | 0 |
| 2.3.2 | 4 | 8.8 | 10.8% | 0 | 0 |
| 2.3.1 | 4 | 8.8 | 10.8% | 0 | 0 |
| 2.3.0 | 8 | 9.0 | 9.3% | 0 | 0 |
| 2.2.7 | 2 | 8.3 | 8.7% | 0 | 0 |
| 2.2.6 | 2 | 8.3 | 8.7% | 0 | 0 |
| 2.2.5 | 2 | 8.3 | 8.7% | 0 | 0 |
| 2.2.4 | 2 | 8.3 | 8.7% | 0 | 0 |
| 2.2.3 | 3 | 8.3 | 6.0% | 0 | 0 |
| 2.2.2 | 7 | 9.2 | 5.3% | 0 | 0 |
| 2.2.1 | 3 | 8.3 | 6.0% | 0 | 0 |
| 2.2.0 | 4 | 7.5 | 7.2% | 0 | 0 |
| 2.1.7 | 2 | 7.8 | 4.1% | 0 | 0 |
| 2.1.6 | 2 | 7.8 | 4.1% | 0 | 0 |