CVE-2026-67991: Ruby Ruby 3.1.x vulnerability
Published Aug 13, 2026
·Updated
crmne/rubyllm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
Affected Software
1 affected component
Ruby Ruby 3.1.x
Event History
Aug 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-67991?
CVE-2026-67991 has a risk rating of 26, indicating a potential for significant impact.
2
How do I fix CVE-2026-67991?
To mitigate CVE-2026-67991, consider avoiding the use of excessively long crafted class, agent, or tool names in Ruby 3.1.x.
3
What software is affected by CVE-2026-67991?
CVE-2026-67991 affects Ruby version 3.1.x, specifically within the crmne/ruby_llm library.
4
What type of vulnerability is CVE-2026-67991?
CVE-2026-67991 is a denial-of-service vulnerability caused by a polynomial-time regular expression.
5
When was CVE-2026-67991 published?
CVE-2026-67991 was published on August 13, 2026.