webrick
RubyGems5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting webrickpage 1 of 1
- CVE-2008-4310HIGHCVSS v2 7.8EG 7.8fixed in 1.3.12008-12-09
httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incompl…
- CVE-2009-4492HIGHCVSS v2 7.5EG 7.5fixed in 1.4.02010-01-13
vulnerable: 1.3.1, 1.4.0.beta1
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attacker…
- CVE-2017-10784HIGHCVSS 8.8EG 8.8fixed in 1.4.02017-09-19
vulnerable: 1.3.1, 1.4.0.beta1
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands vi…
- CVE-2020-25613HIGHCVSS 7.5EG 7.5fixed in 1.6.1, 1.5.1 or 1.4.4, by version range2020-10-06
vulnerable: 1.3.1 ... 1.4.3 (6 versions)
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploi…
- CVE-2025-6442MEDIUMCVSS 5.9EG 5.9fixed in 1.8.22025-06-25
vulnerable: 1.3.1 ... 1.8.1 (14 versions)
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed …
Check whether webrick is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for webrick CVEs against the assets you own.
Book a Demo →