CVE-2014-6438

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

mediumEPSS 4.1%

Description

The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.

Metrics

Severity
medium
no public PoC known
90.2 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
4.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-04-17 23:15 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux9.0

  • linux

    ubuntu / ruby2.3xenial

  • macos

    apple / macos

  • other

    fedoraproject / fedora36

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    ruby-min2.6.0

  • bitnami

    ruby-min2.7.0

  • bitnami

    ruby-min3.0.0

  • bitnami

    ruby-min3.1.0

  • bitnami

    ruby-min3.2.0

  • bitnami

    ruby-min3.3.0

  • bitnami

    ruby-min

  • maven

    org.jruby:jruby0.8.3

  • maven

    org.jruby:jruby0.9.1

  • maven

    org.jruby:jruby0.9.2

  • maven

    org.jruby:jruby0.9.8

  • maven

    org.jruby:jruby0.9.9

  • maven

    org.jruby:jruby1.0

  • maven

    org.jruby:jruby1.0.1

  • maven

    org.jruby:jruby1.0.2

  • maven

    org.jruby:jruby1.0.3

  • maven

    org.jruby:jruby1.0RC1

  • maven

    org.jruby:jruby1.0RC2

  • maven

    org.jruby:jruby1.0RC3

  • maven

    org.jruby:jruby1.1

  • maven

    org.jruby:jruby1.1.1

  • maven

    org.jruby:jruby1.1.2

  • maven

    org.jruby:jruby1.1.3

  • maven

    org.jruby:jruby1.1.4

References & sources

Linked CVEs

Show 11 more CVEs
IDCVE-2014-6438