JLSEC-2026-1291

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1291.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1291.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1291
Upstream
Published
2026-08-13T09:49:53.975Z
Modified
2026-08-13T10:00:07.719094167Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

Database specific
{
    "sources": [
        {
            "imported": "2026-08-12T15:35:15.798Z",
            "id": "CVE-2023-28756",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-28756",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28756",
            "modified": "2026-06-17T05:48:42.103Z",
            "database_specific": {
                "status": "Modified"
            },
            "published": "2023-03-31T04:15:09.090Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / ruby_jll

Package

Name
ruby_jll
Purl
pkg:julia/ruby_jll?uuid=3ea333e9-fd8a-53ca-adba-366e8551b7d5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1291.json"