crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
Title Ruby LLM Regular Expression Denial‑of‑Service on Mistral Capability Matching

Fri, 02 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Title Polynomial‑time Regular Expression Denial of Service in Ruby‑LLM Mistral Capability Matching
Weaknesses CWE-749

Fri, 02 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1333
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Title Polynomial‑time Regular Expression Denial of Service in Ruby‑LLM Mistral Capability Matching
Weaknesses CWE-749

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T19:09:36.496Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67989

cve-icon Vulnrichment

Updated: 2026-10-02T19:08:32.274Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:51.247

Modified: 2026-10-02T20:17:03.933

Link: CVE-2026-67989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:30:10Z

Weaknesses