ruby is vulnerable to Use-After-Free
75
High Risk
Ruby contains a use-after-free vulnerability in the pthread-based getaddrinfo timeout handler used by Addrinfo.getaddrinfo(..., timeout:) and Socket.tcp(..., resolv_timeout:). A remote attacker able to delay DNS responses near the configured timeout may trigger a race condition causing the Ruby process to crash.
You are affected if you are using a version that falls within the vulnerable range.
ruby is vulnerable to Use-After-Free in versions 4.0.0 - 4.0.4.
Upgrade the ruby library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant