Vulnerability Description
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/Zykis1024/9f2d68fa3fd4e3a0ab83063bbe61a8e2
- https://github.com/crmne/ruby_llm
- https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/
- https://github.com/crmne/ruby_llm/commit/9d75b033d7d00c4e1baa9b0afb4828faa8bd660
FAQ
What is CVE-2026-67991?
CVE-2026-67991 is a vulnerability with a CVSS score of 7.5 (HIGH). crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long craf...
How severe is CVE-2026-67991?
CVE-2026-67991 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67991?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.