{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2023-28755: uri redos in the vendored Bundler::URI RFC3986 parser. The\n  same patch also carries the CVE-2023-36617 follow-up hardening (upstream\n  ruby/uri 9d7bcef, 9010ee2): the rfc3986 PORT and rfc2396 ABS_URI / REL_URI\n  leading quantifiers become possessive in every uri copy. No ELSLANG ticket\n  exists for CVE-2023-36617, so it is not listed as a tracked id.\n- CVE-2024-27280: stringio buffer over-read in ungetc/ungetbyte.\n- CVE-2024-27281: rdoc code execution via unrestricted yaml and marshal loads.\n- CVE-2024-27282: regexp arbitrary heap read via unbounded reg->dmin.",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
        "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_ruby/el7/advisories/2026/clsa-2026_1788269949.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-01T13:41:31Z",
      "generator": {
        "date": "2026-09-01T13:41:31Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788269949",
      "initial_release_date": "2026-09-01T13:41:31Z",
      "revision_history": [
        {
          "date": "2026-09-01T13:41:31Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "alt-ruby27: Fix of 14 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-net-telnet@0.2.0-148.el7?arch=noarch&epoch=1&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygems@3.1.6-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-minitest@5.13.0-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-test-unit@3.3.4-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-doc-0:2.7.8-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-doc-0:2.7.8-148.el7.noarch",
                  "product_id": "alt-ruby27-doc-0:2.7.8-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-doc@2.7.8-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-irb@1.2.6-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-power_assert@1.1.7-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygems-devel@3.1.6-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
                  "product_id": "alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-default-gems@2.7.8-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-bundler@2.2.24-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-xmlrpc@0.3.0-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-rake@13.0.1-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
                "product": {
                  "name": "alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
                  "product_id": "alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-rdoc@6.2.1.1-148.el7?arch=noarch&os_name=centos&os_version=7"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
                  "product_id": "alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-bigdecimal@2.0.0-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
                  "product_id": "alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-io-console@0.5.6-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
                  "product_id": "alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-json@2.3.0-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-0:2.7.8-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-0:2.7.8-148.el7.x86_64",
                  "product_id": "alt-ruby27-0:2.7.8-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27@2.7.8-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
                  "product_id": "alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-libs@2.7.8-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
                  "product_id": "alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-psych@3.1.0-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
                  "product_id": "alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-rubygem-openssl@2.1.4-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
                "product": {
                  "name": "alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
                  "product_id": "alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby27-devel@2.7.8-148.el7?arch=x86_64&os_name=centos&os_version=7"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-0:2.7.8-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-0:2.7.8-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-libs-0:2.7.8-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygems-0:3.1.6-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-devel-0:2.7.8-148.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64"
        },
        "product_reference": "alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-doc-0:2.7.8-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-doc-0:2.7.8-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-default-gems-0:2.7.8-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch"
        },
        "product_reference": "alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-27281",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-27281"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1187477",
          "url": "https://hackerone.com/reports/1187477"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/",
          "url": "https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/"
        }
      ],
      "release_date": "2024-05-14T15:11:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-27820",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2026-27820"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/zlib/security/advisories/GHSA-g857-hhfv-j68w",
          "url": "https://github.com/ruby/zlib/security/advisories/GHSA-g857-hhfv-j68w"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/3467067",
          "url": "https://hackerone.com/reports/3467067"
        }
      ],
      "release_date": "2026-04-16T18:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-28755",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2023-28755"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/uri/releases/",
          "url": "https://github.com/ruby/uri/releases/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202401-27",
          "url": "https://security.gentoo.org/glsa/202401-27"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230526-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20230526-0003/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/downloads/releases/",
          "url": "https://www.ruby-lang.org/en/downloads/releases/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/",
          "url": "https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/",
          "url": "https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/05/msg00015.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00015.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        }
      ],
      "release_date": "2023-03-31T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2024-49761",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-49761"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f",
          "url": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761",
          "url": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241227-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20241227-0004/"
        }
      ],
      "release_date": "2024-10-28T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-27280",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-27280"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1399856",
          "url": "https://hackerone.com/reports/1399856"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/",
          "url": "https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2025/Sep/53",
          "url": "http://seclists.org/fulldisclosure/2025/Sep/53"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2025/Sep/54",
          "url": "http://seclists.org/fulldisclosure/2025/Sep/54"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2025/Sep/55",
          "url": "http://seclists.org/fulldisclosure/2025/Sep/55"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250502-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20250502-0003/"
        }
      ],
      "release_date": "2024-05-14T15:11:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2025-61594",
      "cwe": {
        "id": "CWE-200",
        "name": "Exposure of Sensitive Information to an Unauthorized Actor"
      },
      "notes": [
        {
          "category": "description",
          "text": "URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2025-61594"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-22h5-pq3x-2gf2",
          "url": "https://github.com/advisories/GHSA-22h5-pq3x-2gf2"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r",
          "url": "https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2957667",
          "url": "https://hackerone.com/reports/2957667"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2025/02/26/security-advisories",
          "url": "https://www.ruby-lang.org/en/news/2025/02/26/security-advisories"
        }
      ],
      "release_date": "2025-12-30T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-27282",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-27282"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2122624",
          "url": "https://hackerone.com/reports/2122624"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/",
          "url": "https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241011-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20241011-0007/"
        }
      ],
      "release_date": "2024-05-14T15:11:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-27220",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2025-27220"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27220.yml",
          "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27220.yml"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2890322",
          "url": "https://hackerone.com/reports/2890322"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html"
        }
      ],
      "release_date": "2025-03-04T00:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-35176",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": " REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-35176"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb",
          "url": "https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176",
          "url": "https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250306-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20250306-0001/"
        }
      ],
      "release_date": "2024-05-16T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-27219",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2025-27219"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27219.yml",
          "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27219.yml"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2936778",
          "url": "https://hackerone.com/reports/2936778"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html"
        }
      ],
      "release_date": "2025-03-04T00:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-43398",
      "cwe": {
        "id": "CWE-776",
        "name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-43398"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/releases/tag/v3.3.6",
          "url": "https://github.com/ruby/rexml/releases/tag/v3.3.6"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-vmwr-mc7x-5vc3",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vmwr-mc7x-5vc3"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250103-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20250103-0006/"
        }
      ],
      "release_date": "2024-08-22T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2024-41946",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-41946"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368",
          "url": "https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-5866-49gr-22v4",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-5866-49gr-22v4"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml",
          "url": "https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946",
          "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250117-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20250117-0007/"
        }
      ],
      "release_date": "2024-08-01T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-41123",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-41123"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123",
          "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241227-0005/",
          "url": "https://security.netapp.com/advisory/ntap-20241227-0005/"
        }
      ],
      "release_date": "2024-08-01T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-39908",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": " REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`. If you need to parse untrusted XMLs, you many be impacted to these vulnerabilities. The REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. Users are advised to upgrade. Users unable to upgrade should avoid parsing untrusted XML strings.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
          "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
          "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
          "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-39908"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908",
          "url": "https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250117-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20250117-0008/"
        }
      ],
      "release_date": "2024-07-16T18:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:39:10.885229Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949",
          "product_ids": [
            "CentOS-7:alt-ruby27-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-default-gems-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-devel-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-doc-0:2.7.8-148.el7.noarch",
            "CentOS-7:alt-ruby27-libs-0:2.7.8-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bigdecimal-0:2.0.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-bundler-0:2.2.24-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-io-console-0:0.5.6-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-irb-0:1.2.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-json-0:2.3.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-minitest-0:5.13.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-net-telnet-1:0.2.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-openssl-0:2.1.4-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-power_assert-0:1.1.7-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-psych-0:3.1.0-148.el7.x86_64",
            "CentOS-7:alt-ruby27-rubygem-rake-0:13.0.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-rdoc-0:6.2.1.1-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-test-unit-0:3.3.4-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygem-xmlrpc-0:0.3.0-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-0:3.1.6-148.el7.noarch",
            "CentOS-7:alt-ruby27-rubygems-devel-0:3.1.6-148.el7.noarch"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788269949"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    }
  ]
}