R
Ruby
Security Risk Profile
37
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 81 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 1, 2007 to present
81
Total CVEs
8
Critical+High
0
Exploited
6
Unpatched
Threat Assessment
Avg CVSS
4.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
37/100
low
🆕 2Fresh (<7d)📈 2 in Last 30 Days
Severity Distribution
Critical
2High
6Medium
28Low
13Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
5Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
3
2
Race Condition
3
3
Command Injection
2
4
Use After Free
2
5
Infoleak
1
Most Affected Products
1. Ruby Ruby47
2. Ruby REXML5
3. Ruby WEBrick5
4. Ruby json gem4
5. Ruby JSON3
Recent Vulnerabilities
See more →CVE-2026-67991
CVSS 7.5high
Aug 13, 2026🔧 No Patch
CVE-2026-54696
CVSS 3.7low
Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
Jun 30, 2026
CVE-2026-47389
CVSS 8.6high
Mastodon: SSRF protection bypass on older Ruby versions
Jun 24, 2026🔧 No Patch
REDHAT-BUG-2492252
CVSS 7.0high
Jun 24, 2026🔧 No Patch
REDHAT-BUG-2491519
CVSS 4.0medium
Jun 22, 2026🔧 No Patch
REDHAT-BUG-2491523
CVSS 4.0medium
Jun 22, 2026🔧 No Patch
CVE-2026-46727
CVSS 8.1high
May 22, 2026🔧 No Patch
EOL-ruby-4.0
unknown
Dec 25, 2025
CVE-2025-58767
CVSS 1.2low
REXML has a DoS condition when parsing malformed XML file
Sep 17, 2025
CVE-2025-45765
CVSS 9.1critical
Aug 7, 2025🔧 No Patch
Monitor Ruby in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.