CVE-2026-41316Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Patch or workaround signal is available
  • 17 mentions across 8 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 15 signals
  • Disclosure: 9 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 6 mentions (2026-04-21); latest day: 1
  • 17 total mentions across 8 days

Deep dive

Activity timeline17 mentions / 8d
02356Mentions · 2026-04-21: 6Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-04-24: 2Mentions · 2026-04-25: 3Mentions · 2026-05-03: 1Mentions · 2026-05-06: 1Mentions · 2026-09-13: 1Patch / Workaround · 2026-04-21: 4Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-09-13: 1Technical Details · 2026-04-21: 5Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-25: 3Technical Details · 2026-05-03: 1Technical Details · 2026-09-13: 104-2104-2204-2304-2404-2505-0305-0609-13
Signal classification3 categories
Disclosure
952.9%
Patch
741.2%
General
15.9%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-04-216
Disclosure2Patch4
2026-04-222
Disclosure1Patch1
2026-04-231
General1
2026-04-242
Disclosure2
2026-04-253
Disclosure3
2026-05-031
Patch1
2026-05-061
Disclosure1
2026-09-131
Patch1
Full discourse17 posts
  • k0kubun@k0kubun
    Patch

    Ruby 4.0.3 has been released. It updates ERB to 6.0.1.1 for CVE-2026-41316. If your application calls Marshal.load on untrusted data AND has both erb and activesupport loaded, please update your ERB version. You may update Ruby to 4.0.3 to do so. https://www.ruby-lang.org/en/news/2026/04/21/ruby-4-0-3-released/

    Post summary

    Ruby 4.0.3 releases an ERB update to version 6.0.1.1, fixing CVE‑2026‑41316; users running Marshal.load on untrusted data with erb and activesupport should update their Ruby installation to mitigate the vulnerability.

    02205057.8K
    5.5K followersView on X
  • k0kubun@k0kubun
    Patch

    We released ERB 6.0.4, 6.0.1.1, 4.0.4.1, 4.0.3.1, and published security advisory for CVE-2026-41316. If your application calls Marshal.load on untrusted data AND has both erb and activesupport loaded, please update your ERB to one of those versions. https://www.ruby-lang.org/en/news/2026/04/21/erb-cve-2026-41316/

    Post summary

    The text announces the release of patched ERB versions for CVE‑2026‑41316 and urges users to update when their application calls Marshal.load on untrusted data with erb and activesupport loaded.

    11003867.7K
    5.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Ruby, Deserialization RCE, #CVE-2026-41316 (High) https://dailycve.com/ruby-deserialization-rce-cve-2026-41316-high/

    Post summary

    The text announces a high‑severity Ruby deserialization RCE vulnerability (CVE‑2026‑41316), points to a detailed article but does not provide exploitation details, patches, or PoC.

    1001045
    183 followersView on X
  • Ruby Stack News@ruby_stack_news
    Patch

    Ruby 4.0.3 fixes a serious ERB deserialization issue (CVE-2026-41316). ERB#def_method, def_module, def_class bypass the @_init guard → RCE via Marshal.load. Rails apps are especially exposed. Upgrade now. https://rubystacknews.com/2026/04/21/ruby-4-0-3-released-critical-erb-deserialization-fix/ #ruby #rails #security #programming #opensource

    Post summary

    Ruby 4.0.3 releases a patch that fixes an ERB deserialization flaw capable of RCE via Marshal.load, especially impacting Rails applications; users are advised to upgrade immediately.

    0001096
    69 followersView on X
  • ChangeWatch@changewatchdev
    Patch

    Ruby ERB patch fixes CVE-2026-41316 deserialization bypass If your application ever calls Marshal.load on untrusted input and loads both erb and activesupport, a deserialization bypass (CVE-2026-41316) in ERB can let attackers evade the… Read more → http://changewatch.dev/explore/f3e4d198-ce46-4e7f-a7b8-d136a3bbcd9e

    Post summary

    The post announces that a patch has been released to fix the CVE‑2026‑41316 deserialization bypass in Ruby ERB when untrusted input is loaded via `Marshal.load` in conjunction with `erb` and `activesupport`.

    0001060
    3 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    Ruby News ➜ CVE-2026-41316: ERB @_init deserialization guard bypass via def_module / def_method / def_class https://www.ruby-lang.org/en/news/2026/04/21/erb-cve-2026-41316/

    Post summary

    Ruby has disclosed CVE‑2026‑41316, a deserialization guard bypass in ERB involving def_module, def_method, and def_class. No PoC, exploit, patch, or active exploitation claims are provided.

    00010140
    2.7K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-41316: Ruby Unauthenticated Remote Code Execution (Gentoo GLSA-202609-… "Gentoo Linux has published security advisory GLSA-202609-03, disclosing CVE-2026-41316 — a…" 🔗 https://securityarsenal.com/blog/cve-2026-41316-ruby-unauthenticated-remote-code-execution-gentoo-glsa-202609-03-detection-and-remediation-guide #CyberSecurity #ThreatIntel #critical #zeroday #cve

    Post summary

    The tweet announces CVE-2026-41316, an unauthenticated remote code execution vulnerability in Ruby, and points to Gentoo security advisory GLSA-202609-03, indicating a patch is available.

    0000060
    31 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Ruby ❗ CVE-2026-41316 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-ruby/ https://t.co/MstfzoS5F9

    Post summary

    The tweet announces a vulnerability (CVE‑2026‑41316) affecting Ruby products and directs readers to a link for more information, but contains no technical or exploit details.

    0000086
    6.7K followersView on X
  • Vito Botta@vitobotta
    Patch

    Ruby 4.0.3 shipped on April 21 with exactly one change: a fix for CVE-2026-41316 in ERB. If you're rendering untrusted input through ERB templates, there's a code injection path there. The release cadence from the Ruby team is clear: 4.0.3 in May (this was early), 4.0.4 in July, 4.0.5 in September. Two-month cycles through the 4.0 series. Most Rails shops I know are still on 3.4. The jump to 4.0 isn't trivial, Ruby Box and ZJIT are still experimental. But the security patches keep landing for 4.0, and 3.2 hit EOL in March. The clock is ticking. https://www.ruby-lang.org/en/news/2026/04/21/ruby-4-0-3-released/

    Post summary

    Ruby 4.0.3 releases a fix for CVE‑2026‑41316, addressing a code‑injection path in ERB templates; no PoC, exploit, or active exploitation is reported.

    00000110
    963 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41316 ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on http://rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `E… https://www.cve.org/CVERecord?id=CVE-2026-41316

    Post summary

    The text describes a vulnerability in Ruby's ERB templating system involving an `@_init` guard, noting that the fix is available in ERB 2.2.0, with no evidence of exploitation or PoC.

    00000102
    57.2K followersView on X
  • RubyOnRails.BA@RubyOnRailsBa
    Disclosure

    CVE-2026-41316: ERB @_init deserialization guard bypass via def_module / def_method / def_class | Ruby (from 24/04/2026) #ruby #rubyonrails #programming #CVE-2026-41316: #@_init #deserialization #guard #bypass #def_module #def_method #def_class https://www.rubyonrails.ba/link/cve-2026-41316-erb-_init-deserialization-guard-bypass-via-def_module-def_method-def_class-ruby

    Post summary

    The text announces a new vulnerability (CVE-2026-41316) in Ruby on Rails, providing technical details about the bypass but no PoC, exploit code, or patch information.

    0000051
    482 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-41316 impacts erb in 3 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/484 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The post announces a newly discovered high-severity CVE targeting erb in AWS Lambda base images, providing basic identification details but no exploit, patch, or PoC information.

    0000035
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41316 ERB Deserialization Guard Bypass Enables Arbitrary Code Execution in Ruby on Rails https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41316

    Post summary

    The text announces CVE-2026-41316, describing an ERB deserialization guard bypass in Ruby on Rails that enables arbitrary code execution, but does not provide PoC, exploit, patch, or evidence of active exploitation.

    0000081
    4.0K followersView on X
  • 貧困女子ちゃん@w08fGrbtsG5ElJ9
    General

    その危険極まりないerbオブジェクトに対して、何とかしてメソッドを呼び出すというのが CVE-2026-41316 ってことになる。 https://x.com/w08fGrbtsG5ElJ9/status/2047123136597168434

    Post summary

    The tweet points out CVE‑2026‑41316 involving a dangerous ERB object but provides no PoC, exploit, or patch information.

    00000136
    458 followersView on X
  • けいご@keigoriankami
    Disclosure

    CVE-2026-41316: ERB @_init deserialization guard bypass via def_module / def_method / def_class https://www.ruby-lang.org/en/news/2026/04/21/erb-cve-2026-41316/

    Post summary

    Ruby core announces CVE-2026-41316, a deserialization guard bypass involving def_module, def_method, and def_class, but provides no PoC, exploitation details, or patch information.

    0000040
    43 followersView on X
  • ruby-news.kr@rubynewskr
    Disclosure

    CVE-2026-41316: ERB 역직렬화 가드 우회 및 임의 코드 실행 취약점 ERB 객체 역직렬화 시 @_init 가드를 우회하여 임의 코드를 실행할 수 있는 CVE-2026-41316 취약점이 발견되었다. https://ruby-news.kr/articles/cve-2026-41316-erb-_init-deserialization-guard-bypass-via-def_module-def_method-def_class

    Post summary

    The article announces the discovery of CVE‑2026‑41316, an ERB deserialization guard bypass that enables arbitrary code execution.

    0000065
    18 followersView on X
  • ruby-news.kr@rubynewskr
    Patch

    Ruby 4.0.3 릴리스: ERB 보안 취약점 수정 ERB 6.0.1.1 업데이트를 통해 신뢰할 수 없는 데이터의 Marshal.load와 관련된 보안 취약점(CVE-2026-41316)을 해결했다. https://ruby-news.kr/articles/ruby-4-0-3-released

    Post summary

    Ruby 4.0.3 releases an ERB update (6.0.1.1) that fixes CVE-2026-41316, which involves untrusted Marshal.load usage. The post is a patch announcement with no exploit or PoC evidence.

    0000075
    18 followersView on X

Explore more