CVE-2026-41316: CWE-693: Protection Mechanism Failure in ruby erb
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
AI Analysis
Technical Summary
This advisory covers several vulnerabilities in Ruby as distributed by Red Hat. The most critical is CVE-2026-41316, an arbitrary code execution vulnerability in ERB caused by a deserialization bypass that allows attackers to execute code by exploiting untrusted data deserialization. Additional vulnerabilities include IMAP command injection via symbol arguments (CVE-2026-42258), denial of service via crafted IMAP responses (CVE-2026-42245), and information disclosure through man-in-the-middle attacks bypassing TLS (CVE-2026-42246). Red Hat has issued patches for these vulnerabilities in Ruby packages for Red Hat Enterprise Linux 9.6 Extended Update Support and related distributions. The advisory includes detailed CVSS scoring for CVE-2026-41316 with a base score of 8.1, indicating high severity.
Potential Impact
Successful exploitation of CVE-2026-41316 can lead to arbitrary code execution without requiring privileges or user interaction, potentially compromising system integrity, confidentiality, and availability. The IMAP-related vulnerabilities can result in command injection, denial of service, or information disclosure, impacting the security of applications using Ruby's Net::IMAP library. These vulnerabilities collectively pose a high risk to affected systems if unpatched.
Mitigation Recommendations
Red Hat has released official security updates that address these vulnerabilities. Users should apply the provided patches promptly by updating Ruby packages to the fixed versions as detailed in the Red Hat advisory RHSA-2026:33462. For update instructions, refer to https://access.redhat.com/articles/11258. No additional mitigations are specified or required beyond applying the official fixes.
CVE-2026-41316: CWE-693: Protection Mechanism Failure in ruby erb
Description
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
CVSS v3.1
Score 8.1high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers several vulnerabilities in Ruby as distributed by Red Hat. The most critical is CVE-2026-41316, an arbitrary code execution vulnerability in ERB caused by a deserialization bypass that allows attackers to execute code by exploiting untrusted data deserialization. Additional vulnerabilities include IMAP command injection via symbol arguments (CVE-2026-42258), denial of service via crafted IMAP responses (CVE-2026-42245), and information disclosure through man-in-the-middle attacks bypassing TLS (CVE-2026-42246). Red Hat has issued patches for these vulnerabilities in Ruby packages for Red Hat Enterprise Linux 9.6 Extended Update Support and related distributions. The advisory includes detailed CVSS scoring for CVE-2026-41316 with a base score of 8.1, indicating high severity.
Potential Impact
Successful exploitation of CVE-2026-41316 can lead to arbitrary code execution without requiring privileges or user interaction, potentially compromising system integrity, confidentiality, and availability. The IMAP-related vulnerabilities can result in command injection, denial of service, or information disclosure, impacting the security of applications using Ruby's Net::IMAP library. These vulnerabilities collectively pose a high risk to affected systems if unpatched.
Mitigation Recommendations
Red Hat has released official security updates that address these vulnerabilities. Users should apply the provided patches promptly by updating Ruby packages to the fixed versions as detailed in the Red Hat advisory RHSA-2026:33462. For update instructions, refer to https://access.redhat.com/articles/11258. No additional mitigations are specified or required beyond applying the official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20670
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a160980e29bf47b5064cc87
Added to database: 05/26/2026, 20:58:40 UTC
Last enriched: 08/17/2026, 19:06:31 UTC
Last updated: 09/15/2026, 00:26:35 UTC
Views: 87
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.