CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
{ "vanir_signatures": [ { "id": "CVE-2021-41819-2f76299c", "signature_type": "Function", "target": { "file": "ext/cgi/escape/escape.c", "function": "optimized_escape_html" }, "deprecated": false, "digest": { "length": 658.0, "function_hash": "185553476159107413192269642060714357735" }, "signature_version": "v1", "source": "https://github.com/ruby/ruby/commit/f69aeb83146be640995753667fdd6c6f157527f5" }, { "id": "CVE-2021-41819-799f160e", "signature_type": "Line", "target": { "file": "ext/cgi/escape/escape.c" }, "deprecated": false, "digest": { "line_hashes": [ "221608888545214764521643589590002473795", "62837079863855754692353823286478885059", "151633818343694841750591657495653307518", "112628295566100827065348454738811594068" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/ruby/ruby/commit/f69aeb83146be640995753667fdd6c6f157527f5" } ] }