Skip to main content

Threats Tagged 'cve-2026-27820'

View all threats tagged with 'cve-2026-27820'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-27820

Threats Tagged 'cve-2026-27820'

Click on any threat for detailed analysis and mitigation recommendations

Multiple security vulnerabilities have been identified and addressed in the Ruby 4.0 module for Red Hat Enterprise Linux 9. These include memory corruption via buffer overflow in Zlib::GzipReader, several arbitrary IMAP command injection flaws, and denial of service issues related to Net::IMAP. The update rebases Ruby 4.0 to the latest release and includes bug fixes and enhancements. The advisory rates the security impact as Important and provides updated packages for affected Red Hat Enterprise Linux 9 variants.

Join the discussion

This Red Hat Security Advisory addresses multiple vulnerabilities in Ruby 3.3, including memory corruption via buffer overflow in Zlib::GzipReader, arbitrary IMAP command injection through unvalidated input, and denial of service via malformed or large iteration count inputs in Net::IMAP. The update rebases Ruby 3.3 to the latest release and includes bug fixes and enhancements. The advisory affects Red Hat Enterprise Linux 9 and related variants. No CVSS scores are provided, but the vulnerabilities are rated as having a high security impact.

Join the discussion

Multiple security vulnerabilities have been identified and fixed in Ruby as part of a Red Hat security advisory. These include memory corruption via buffer overflow in Zlib::GzipReader, arbitrary IMAP command injection through various input validation flaws, and denial of service conditions in Net::IMAP. The advisory also includes bug fixes and enhancements, rebasing Ruby to the latest 3.3 release. The update is rated as important by Red Hat Product Security and affects Red Hat Enterprise Linux 10 and related products.

Join the discussion

Red Hat has issued a security advisory for ruby4.0 addressing multiple vulnerabilities including memory corruption via buffer overflow in Zlib::GzipReader, arbitrary IMAP command injection through various input validation flaws, and denial of service via malformed or large iteration count inputs in Net::IMAP. The update rebases ruby4.0 to the latest Ruby 4.0 release and includes bug fixes and enhancements. These vulnerabilities affect Red Hat Enterprise Linux 10 and related products. The advisory rates the security impact as Important and provides updated packages to remediate these issues.

Join the discussion

Red Hat has issued a security advisory for the ruby:3.3 module in Red Hat Enterprise Linux 8, addressing multiple vulnerabilities including memory corruption via buffer overflow in Zlib::GzipReader, arbitrary IMAP command injection through various input validation flaws, and denial of service via malformed or large iteration count inputs in Net::IMAP. The update rebases Ruby 3.3 to the latest release, incorporating these security fixes along with bug fixes and enhancements.

Join the discussion

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2026-27820
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses