CVE-2026-46727Patch(ruby-lang / ruby)

MEDIUMCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch ruby-lang ruby systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-based exploitation is theoretically possible. The attack could, for example, be carried out through a crafted authoritative DNS server or recursive resolver.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ruby

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-12)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
ruby

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-09-12: 2Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 105-2005-2109-12
Signal classification3 categories
Patch
250.0%
Active Exploitation
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-201
Patch1
2026-05-211
Patch1
2026-09-122
Active Exploitation1Disclosure1
Full discourse4 posts
  • k0kubun@k0kubun
    Patch

    We released Ruby 4.0.5 and published security advisory for CVE-2026-46727. If you use Ruby 4.0.0~4.0.4, we recommend updating your Ruby version to 4.0.5. https://www.ruby-lang.org/en/news/2026/05/20/ruby-4-0-5-released/

    Post summary

    Ruby 4.0.5 has been released with a security advisory for CVE-2026-46727; users of Ruby 4.0.0‑4.0.4 are urged to upgrade.

    04511161113.8K
    5.5K followersView on X
  • 𝕸𝖎𝖘𝖘𝖞 𝕯@LadyDucati
    Disclosure

    @cantinasecurity @tenbinlabs Did you know this? (during finding incident CVE-2026-46727 in May at Rubygems) https://t.co/ZfsDjmMOsH

    Post summary

    The tweet announces the discovery of CVE-2026-46727 at Rubygems but provides no further technical detail, PoC, or exploitation context.

    00001162
    672 followersView on X
  • 𝕸𝖎𝖘𝖘𝖞 𝕯@LadyDucati
    Active Exploitation

    @coe401_ Did you notice anything about the https://open.ai model breakout hack in May during patching incident CVE-2026-46727 in the same time at @rubygems ? https://t.co/U5274asP0S

    Post summary

    The tweet references a real‑world breakout hack linked to CVE‑2026‑46727, but it lacks technical, PoC, or patch details, leaving the precise nature of the vulnerability unclear.

    0000078
    672 followersView on X
  • Chart Design@ChartDesign
    Patch

    【プログラミングニュース 第21週】 今週のハイライト: - Node.js v24.16.0 LTS + v26.2.0 同時リリース - KotlinConf 2026:VS Code公式Alpha対応 - WordPress 7.0 メジャーリリース - Ruby 4.0.5 セキュリティ修正(CVE-2026-46727) - Misskey:5件のCVE修正 📺 https://youtu.be/uJFT63dY4BY

    Post summary

    The article announces that Ruby 4.0.5 includes a security fix for CVE‑2026‑46727, with no additional exploit or technical detail provided.

    00000187
    21 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appruby-langruby---

Explore more