CVE-2026-67987: Crmne ruby_llm vulnerability

Published Sep 29, 2026
·
Updated

crmne/rubyllm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two consecutive regular expressions and delay chat-completion processing

Affected Software

1 affected component
crmne ruby_llm=fa6f279847d6d7027814539d9c0dfc3bbdfd2a83

Event History

Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description

Frequently Asked Questions

1

What input is needed to trigger the excessive CPU consumption?

A model response must contain many unterminated <think> tags. The issue occurs while the library parses think-tag content during chat-completion processing.

2

Which runtime is identified as affected?

The reported condition applies to Ruby 3.1.x at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83.

3

What operational impact should users expect?

The two consecutive regular-expression evaluations can consume excessive CPU and delay chat-completion processing. The reported impact is denial of service through processing delay rather than a stated data-access or code-execution impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203