Security Arsenal, LLC[verified]@SecurityAr58409Patch
The tweet announces CVE-2026-41316, an unauthenticated remote code execution vulnerability in Ruby, and points to Gentoo security advisory GLSA-202609-03, indicating a patch is available.
Vito Botta[verified]@vitobottaPatch
Ruby 4.0.3 releases a fix for CVE‑2026‑41316, addressing a code‑injection path in ERB templates; no PoC, exploit, or active exploitation is reported.
k0kubun@k0kubunPatch
Ruby 4.0.3 releases an ERB update to version 6.0.1.1, fixing CVE‑2026‑41316; users running Marshal.load on untrusted data with erb and activesupport should update their Ruby installation to mitigate the vulnerability.
k0kubun@k0kubunPatch
The text announces the release of patched ERB versions for CVE‑2026‑41316 and urges users to update when their application calls Marshal.load on untrusted data with erb and activesupport loaded.
DailyCVE@dailycveDisclosure
The text announces a high‑severity Ruby deserialization RCE vulnerability (CVE‑2026‑41316), points to a detailed article but does not provide exploitation details, patches, or PoC.
Ruby Stack News@ruby_stack_newsPatch
Ruby 4.0.3 releases a patch that fixes an ERB deserialization flaw capable of RCE via Marshal.load, especially impacting Rails applications; users are advised to upgrade immediately.
ChangeWatch@changewatchdevPatch
The post announces that a patch has been released to fix the CVE‑2026‑41316 deserialization bypass in Ruby ERB when untrusted input is loaded via `Marshal.load` in conjunction with `erb` and `activesupport`.
RUBYLAND@rubylandnewsDisclosure
Ruby has disclosed CVE‑2026‑41316, a deserialization guard bypass in ERB involving def_module, def_method, and def_class. No PoC, exploit, patch, or active exploitation claims are provided.