GHSA-mx5j-mp4f-g8jgHighCVSS 8.1

Savon::Model evaluates WSDL operation names as Ruby source

Published
July 31, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Savon::Model generated SOAP operation methods by interpolating operation names into Ruby source passed to module_eval. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the .all_operations class method provided by Savon::Model to automatically register all operations provided by the WSDL. Configuring Savon::Model with trusted operation names via .operations is safe.

Patches

Patched in Savon 2.17.2.

Users should upgrade to 2.17.2 or later.

Workarounds

Avoid .all_operations for untrusted WSDL documents. Use .operations with trusted operation names instead.

🎯 Affected products1

  • rubygems/savon:>= 0.9.8, < 2.17.2

🔗 References (6)