RHSA-2026:20606HighCVSS 9.1

Red Hat Security Advisory: ruby4.0 security update

Published
May 26, 2026
Last Modified
May 26, 2026

🔗 CVE IDs covered (2)

CVE-2026-33210 · pendingCVE-2026-41316

📋 Description

CVE-2026-33210 — ruby/json: Ruby JSON: Denial of Service or Information Disclosure via format string injection CVE-2026-41316 — erb: ERB: Arbitrary code execution via deserialization bypass

🔗 References (5)