Debian Ruby-Addressable vulnerabilities
2 known vulnerabilities affecting debian/ruby-addressable.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-35611HIGHCVSS 7.52026
CVE-2026-35611 [HIGH] CVE-2026-35611: ruby-addressable - Addressable is an alternative implementation to the URI implementation that is p...
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Templates using the * (explode) modifier with any expansion operat
debian
CVE-2021-32740HIGHCVSS 7.5fixed in ruby-addressable 2.7.0-2 (bookworm)2021
CVE-2021-32740 [HIGH] CVE-2021-32740: ruby-addressable - Addressable is an alternative implementation to the URI implementation that is p...
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to
debian