CVE-2026-67989: Crmne ruby_llm vulnerability
crmne/rubyllm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
crmne/rubyllm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
The affected code is the Mistral model capability matching logic in crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83, when running on Ruby 3.1.x. Deployments that do not exercise this Mistral capability-matching path are not identified by the provided data as exposed.
The issue is a polynomial-time regular expression denial-of-service condition in Mistral model capability matching. The provided data does not specify the exact input source, attacker access level, or triggering string.
A subsequent crmne/ruby_llm commit, dd3c84812598def03d4aff77b5447c41d8f5c34e, is referenced. The provided data does not state which release includes it or describe any mitigation for environments that cannot apply the fix immediately.