VDB
RLSA-2025%3A4487
RLSA-2025%3A4487
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * CGI: ReDoS in CGI::Util#escapeElement (CVE-2025-27220) * CGI: Denial of Service in CGI::Cookie.parse (CVE-2025-27219) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rocky Linux:9 | ruby | 0, 0 |
Timeline
- Jul 29, 2025 CVE Published
- Oct 7, 2025 CVE Updated
- May 1, 2026 Distribution Patch