{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2023-28755: uri ReDoS in the RFC3986 parser via a crafted long URI.\n- CVE-2023-36617: uri ReDoS remaining in both parsers after the incomplete\n  CVE-2023-28755 fix (rfc3986 PORT component, rfc2396 ABS_URI/REL_URI).\n- CVE-2024-27280: stringio buffer overread in ungetc/ungetbyte.\n- CVE-2024-27281: rdoc code execution via .rdoc_options and the ri cache.\n- CVE-2024-27282: regexp arbitrary heap read via unbounded reg->dmin in the\n  Onigmo search.",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
        "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_ruby/el9/advisories/2026/clsa-2026_1788338284.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-02T08:40:36Z",
      "generator": {
        "date": "2026-09-02T08:40:36Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788338284",
      "initial_release_date": "2026-09-02T08:40:36Z",
      "revision_history": [
        {
          "date": "2026-09-02T08:40:36Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "alt-ruby26: Fix of 17 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 9",
                "product": {
                  "name": "Community Enterprise Operating System 9",
                  "product_id": "CentOS-9",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:9:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygems@3.0.3.1-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-openssl@2.1.2-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-power_assert@1.1.3-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-psych@3.1.0-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-xmlrpc@0.3.0-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-0:2.6.10-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-0:2.6.10-18.el9.x86_64",
                  "product_id": "alt-ruby26-0:2.6.10-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26@2.6.10-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-rdoc@6.1.2.1.0-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-test-unit@3.2.9-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
                  "product_id": "alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-devel-doc@2.6.10-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-rake@12.3.3-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-net-telnet@0.2.0-18.el9?arch=x86_64&epoch=1&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-io-console@0.4.7-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-bigdecimal@1.4.1.0-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
                  "product_id": "alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-devel@2.6.10-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
                  "product_id": "alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-libs@2.6.10-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-minitest@5.11.3-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-did_you_mean@1.3.0-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
                "product": {
                  "name": "alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
                  "product_id": "alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-rubygem-json@2.1.0-18.el9?arch=x86_64&os_name=centos&os_version=9"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-ruby26-doc-0:2.6.10-18.el9.noarch",
                "product": {
                  "name": "alt-ruby26-doc-0:2.6.10-18.el9.noarch",
                  "product_id": "alt-ruby26-doc-0:2.6.10-18.el9.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-ruby26-doc@2.6.10-18.el9?arch=noarch&os_name=centos&os_version=9"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-doc-0:2.6.10-18.el9.noarch as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch"
        },
        "product_reference": "alt-ruby26-doc-0:2.6.10-18.el9.noarch",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-0:2.6.10-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-0:2.6.10-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-devel-0:2.6.10-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-libs-0:2.6.10-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64 as a component of Community Enterprise Operating System 9",
          "product_id": "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64"
        },
        "product_reference": "alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
        "relates_to_product_reference": "CentOS-9"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-27281",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-27281"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1187477",
          "url": "https://hackerone.com/reports/1187477"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/",
          "url": "https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/"
        }
      ],
      "release_date": "2024-05-14T15:11:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-27820",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2026-27820"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/zlib/security/advisories/GHSA-g857-hhfv-j68w",
          "url": "https://github.com/ruby/zlib/security/advisories/GHSA-g857-hhfv-j68w"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/3467067",
          "url": "https://hackerone.com/reports/3467067"
        }
      ],
      "release_date": "2026-04-16T18:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-28756",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2023-28756"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/time/releases/",
          "url": "https://github.com/ruby/time/releases/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202401-27",
          "url": "https://security.gentoo.org/glsa/202401-27"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230526-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20230526-0004/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/downloads/releases/",
          "url": "https://www.ruby-lang.org/en/downloads/releases/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/",
          "url": "https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2023/03/30/redos-in-time-cve-2023-28756/",
          "url": "https://www.ruby-lang.org/en/news/2023/03/30/redos-in-time-cve-2023-28756/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        }
      ],
      "release_date": "2023-03-31T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-28755",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2023-28755"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/uri/releases/",
          "url": "https://github.com/ruby/uri/releases/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202401-27",
          "url": "https://security.gentoo.org/glsa/202401-27"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230526-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20230526-0003/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/downloads/releases/",
          "url": "https://www.ruby-lang.org/en/downloads/releases/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/",
          "url": "https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/",
          "url": "https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/05/msg00015.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00015.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        }
      ],
      "release_date": "2023-03-31T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2021-33621",
      "cwe": {
        "id": "CWE-74",
        "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2021-33621"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/06/msg00012.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00012.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQR7LWED6VAPD5ATYOBZIGJQPCUBRJBX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQR7LWED6VAPD5ATYOBZIGJQPCUBRJBX/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THVTYHHEOVLQFCFHWURZYO7PVUPBHRZD/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THVTYHHEOVLQFCFHWURZYO7PVUPBHRZD/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YACE6ORF2QBXXBK2V2CM36D7TZMEJVAS/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YACE6ORF2QBXXBK2V2CM36D7TZMEJVAS/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202401-27",
          "url": "https://security.gentoo.org/glsa/202401-27"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20221228-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20221228-0004/"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2022/11/22/http-response-splitting-in-cgi-cve-2021-33621/",
          "url": "https://www.ruby-lang.org/en/news/2022/11/22/http-response-splitting-in-cgi-cve-2021-33621/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        }
      ],
      "release_date": "2022-11-18T23:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2021-43809",
      "cwe": {
        "id": "CWE-88",
        "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external code, unless that's explicit in the ruby code inside the `Gemfile` itself. However, if the `Gemfile` includes `gem` entries that use the `git` option with invalid, but seemingly harmless, values with a leading dash, this can be false. To handle dependencies that come from a Git repository instead of a registry, Bundler uses various commands, such as `git clone`. These commands are being constructed using user input (e.g. the repository URL). When building the commands, Bundler versions before 2.2.33 correctly avoid Command Injection vulnerabilities by passing an array of arguments instead of a command string. However, there is the possibility that a user input starts with a dash (`-`) and is therefore treated as an optional argument instead of a positional one. This can lead to Code Execution because some of the commands have options that can be leveraged to run arbitrary executables. Since this value comes from the `Gemfile` file, it can contain any character, including a leading dash.\n\nTo exploit this vulnerability, an attacker has to craft a directory containing a `Gemfile` file that declares a dependency that is located in a Git repository. This dependency has to have a Git URL in the form of `-u./payload`. This URL will be used to construct a Git clone command but will be interpreted as the upload-pack argument. Then this directory needs to be shared with the victim, who then needs to run a command that evaluates the Gemfile, such as `bundle lock`, inside.\n\nThis vulnerability can lead to Arbitrary Code Execution, which could potentially lead to the takeover of the system. However, the exploitability is very low, because it requires a lot of user interaction. Bundler 2.2.33 has patched this problem by inserting `--` as an argument before any positional arguments to those Git commands that were affected by this issue. Regardless of whether users can upgrade or not, they should review any untrustred `Gemfile`'s before running any `bundler` commands that may read them, since they can contain arbitrary ruby code.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2021-43809"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubygems/rubygems/commit/0fad1ccfe9dd7a3c5b82c1496df3c2b4842870d3",
          "url": "https://github.com/rubygems/rubygems/commit/0fad1ccfe9dd7a3c5b82c1496df3c2b4842870d3"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubygems/rubygems/commit/a4f2f8ac17e6ce81c689527a8b6f14381060d95f",
          "url": "https://github.com/rubygems/rubygems/commit/a4f2f8ac17e6ce81c689527a8b6f14381060d95f"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubygems/rubygems/pull/5142",
          "url": "https://github.com/rubygems/rubygems/pull/5142"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubygems/rubygems/security/advisories/GHSA-fj7f-vq84-fh43",
          "url": "https://github.com/rubygems/rubygems/security/advisories/GHSA-fj7f-vq84-fh43"
        },
        {
          "category": "external",
          "summary": "https://www.sonarsource.com/blog/securing-developer-tools-package-managers/",
          "url": "https://www.sonarsource.com/blog/securing-developer-tools-package-managers/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/05/msg00015.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00015.html"
        }
      ],
      "release_date": "2021-12-08T19:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-49761",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-49761"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f",
          "url": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761",
          "url": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241227-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20241227-0004/"
        }
      ],
      "release_date": "2024-10-28T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-27280",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-27280"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1399856",
          "url": "https://hackerone.com/reports/1399856"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/",
          "url": "https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2025/Sep/53",
          "url": "http://seclists.org/fulldisclosure/2025/Sep/53"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2025/Sep/54",
          "url": "http://seclists.org/fulldisclosure/2025/Sep/54"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2025/Sep/55",
          "url": "http://seclists.org/fulldisclosure/2025/Sep/55"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250502-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20250502-0003/"
        }
      ],
      "release_date": "2024-05-14T15:11:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2025-61594",
      "cwe": {
        "id": "CWE-200",
        "name": "Exposure of Sensitive Information to an Unauthorized Actor"
      },
      "notes": [
        {
          "category": "description",
          "text": "URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2025-61594"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-22h5-pq3x-2gf2",
          "url": "https://github.com/advisories/GHSA-22h5-pq3x-2gf2"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r",
          "url": "https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2957667",
          "url": "https://hackerone.com/reports/2957667"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2025/02/26/security-advisories",
          "url": "https://www.ruby-lang.org/en/news/2025/02/26/security-advisories"
        }
      ],
      "release_date": "2025-12-30T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-27282",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-27282"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2122624",
          "url": "https://hackerone.com/reports/2122624"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/",
          "url": "https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241011-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20241011-0007/"
        }
      ],
      "release_date": "2024-05-14T15:11:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-27220",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2025-27220"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27220.yml",
          "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27220.yml"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2890322",
          "url": "https://hackerone.com/reports/2890322"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html"
        }
      ],
      "release_date": "2025-03-04T00:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-35176",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": " REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-35176"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb",
          "url": "https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176",
          "url": "https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250306-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20250306-0001/"
        }
      ],
      "release_date": "2024-05-16T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-27219",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2025-27219"
        },
        {
          "category": "external",
          "summary": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27219.yml",
          "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27219.yml"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2936778",
          "url": "https://hackerone.com/reports/2936778"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html"
        }
      ],
      "release_date": "2025-03-04T00:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-43398",
      "cwe": {
        "id": "CWE-776",
        "name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, this vulnerability is not affected. The REXML gem 3.3.6 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-43398"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/releases/tag/v3.3.6",
          "url": "https://github.com/ruby/rexml/releases/tag/v3.3.6"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-vmwr-mc7x-5vc3",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vmwr-mc7x-5vc3"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250103-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20250103-0006/"
        }
      ],
      "release_date": "2024-08-22T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2024-41946",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-41946"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368",
          "url": "https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-5866-49gr-22v4",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-5866-49gr-22v4"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml",
          "url": "https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946",
          "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250117-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20250117-0007/"
        }
      ],
      "release_date": "2024-08-01T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-41123",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-41123"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-r55c-59qm-vjw6"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123",
          "url": "https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241227-0005/",
          "url": "https://security.netapp.com/advisory/ntap-20241227-0005/"
        }
      ],
      "release_date": "2024-08-01T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-39908",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": " REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`. If you need to parse untrusted XMLs, you many be impacted to these vulnerabilities. The REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. Users are advised to upgrade. Users unable to upgrade should avoid parsing untrusted XML strings.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
          "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
          "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-ruby/cve/CVE-2024-39908"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908",
          "url": "https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250117-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20250117-0008/"
        }
      ],
      "release_date": "2024-07-16T18:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T08:38:05.920744Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284",
          "product_ids": [
            "CentOS-9:alt-ruby26-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-devel-doc-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-doc-0:2.6.10-18.el9.noarch",
            "CentOS-9:alt-ruby26-libs-0:2.6.10-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-bigdecimal-0:1.4.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-did_you_mean-0:1.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-io-console-0:0.4.7-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-json-0:2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-minitest-0:5.11.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-net-telnet-1:0.2.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-openssl-0:2.1.2-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-power_assert-0:1.1.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-psych-0:3.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rake-0:12.3.3-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-rdoc-0:6.1.2.1.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-test-unit-0:3.2.9-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygem-xmlrpc-0:0.3.0-18.el9.x86_64",
            "CentOS-9:alt-ruby26-rubygems-0:3.0.3.1-18.el9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-ruby/releases/CLSA-2026:1788338284"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    }
  ]
}