Vulnerability Description
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/crmne/ruby_llm
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/
- https://github.com/crmne/ruby_llm/commit/dd3c84812598def03d4aff77b5447c41d8f5c34
FAQ
What is CVE-2026-67989?
CVE-2026-67989 is a vulnerability with a CVSS score of 7.5 (HIGH). crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
How severe is CVE-2026-67989?
CVE-2026-67989 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67989?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.