Skip to content

Commit 94dccfd

Browse files
authored
Merge pull request #1254 from jasnow/ruby_llm-advs
Two new ruby_llm advisories \@simi - Thanks for reviewing and approving PR.
2 parents 17b65d0 + 24567c7 commit 94dccfd

2 files changed

Lines changed: 59 additions & 0 deletions

File tree

‎gems/ruby_llm/CVE-2026-67987.yml‎

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
---
2+
gem: ruby_llm
3+
cve: 2026-67987
4+
ghsa: 5m38-526f-3498
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-67987
6+
title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
7+
date: 2026-10-01
8+
description: |
9+
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
10+
contains polynomial-time regular expression denial-of-service
11+
conditions in think-tag response parsing on Ruby 3.1.x.
12+
A malicious or anomalous model response containing many unterminated
13+
tags can cause excessive CPU consumption in two consecutive
14+
regular expressions and delay chat-completion processing.
15+
cvss_v3: 7.5
16+
unaffected_versions:
17+
- "< 0.1.0.pre42"
18+
patched_versions:
19+
- ">= 2.0.0.rc1"
20+
related:
21+
url:
22+
- https://nvd.nist.gov/vuln/detail/CVE-2026-67987
23+
- https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
24+
- https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
25+
- https://github.com/crmne/ruby_llm/commit/5e88411f171721b381853fa77d254e266dcf6ad8
26+
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/protocols/chat_completions/chat.rb#L355-L356
27+
- https://github.com/advisories/GHSA-5m38-526f-3498
28+
notes: |
29+
- cvss_v3 from nvd.nist.gov and GHSA URL
30+
- /commit/ URL mentioend this CVE number and patch version.
31+
- Unreviewed GHSA advisory

‎gems/ruby_llm/CVE-2026-67989.yml‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
---
2+
gem: ruby_llm
3+
cve: 2026-67989
4+
ghsa: 57hg-jgw4-wcqw
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-67989
6+
title: Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
7+
date: 2026-10-01
8+
description: |
9+
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83
10+
contains a polynomial-time regular expression denial-of-service
11+
condition in Mistral model capability matching on Ruby 3.1.x.
12+
cvss_v3: 7.5
13+
unaffected_versions:
14+
- "< 0.1.0.pre42"
15+
patched_versions:
16+
- ">= 2.0.0.rc1"
17+
related:
18+
url:
19+
- https://nvd.nist.gov/vuln/detail/CVE-2026-67989
20+
- https://github.com/crmne/ruby_llm/releases#release-v2.0.0.rc1
21+
- https://rubygems.org/gems/ruby_llm/versions/2.0.0.rc1
22+
- https://github.com/crmne/ruby_llm/commit/dd3c84812598def03d4aff77b5447c41d8f5c34e
23+
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/providers/mistral/capabilities.rb#L92
24+
- https://github.com/advisories/GHSA-57hg-jgw4-wcqw
25+
notes: |
26+
- cvss_v3 from nvd.nist.gov and GHSA URL
27+
- /commit/ URL mentioend this CVE number and patch version.
28+
- Unreviewed GHSA advisory

0 commit comments

Comments
 (0)