CVE-2026-67991

Source
https://cve.org/CVERecord?id=CVE-2026-67991
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67991.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67991
Published
2026-08-13T00:00:00Z
Modified
2026-09-06T03:47:04.799442954Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67991.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/crmne/ruby_llm

Affected ranges

Type
GIT
Repo
https://github.com/crmne/ruby_llm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.1.0.pre42
1.*
1.0.0
1.0.1
1.1.0
1.1.0rc1
1.1.0rc2
1.1.1
1.1.2
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.15.0
1.16.0
1.2.0
1.3.0
1.3.0rc1
1.3.1
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67991.json"