CVE-2017-0903: Critical severity Rubygems RubyGems vulnerability
Last updated 18 August 2025
Other sources
RubyGems version 2.0.0 to 2.6.13 is vulnerable to an unsafe object deserialization through a specially crafted YAML formatted gem specification that could lead to a remote code execution when parsed without safegards. Applications that process Gems on the server are impacted but not if rubygems is only used as a client.
References:
http://www.openwall.com/lists/oss-security/2017/10/10/2
— Red Hat
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0903?
CVE-2017-0903 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2017-0903?
To fix CVE-2017-0903, upgrade RubyGems to version 2.6.14 or later.
Which versions of RubyGems are affected by CVE-2017-0903?
RubyGems versions 2.0.0 through 2.6.13 are affected by CVE-2017-0903.
What kinds of applications are impacted by CVE-2017-0903?
Applications that process Gems on the server side are impacted by CVE-2017-0903.
Is there a workaround for CVE-2017-0903?
There is no documented workaround for CVE-2017-0903 other than upgrading RubyGems.