ruby is vulnerable to Use-After-Free
75
High Risk
Ruby contains a use-after-free vulnerability in the pthread-based getaddrinfo timeout handler used by Addrinfo.getaddrinfo(..., timeout:) and Socket.tcp(..., resolv_timeout:). A remote attacker able to delay DNS responses near the configured timeout may trigger a race condition causing the Ruby process to crash.
You are affected if you are using a version that falls within the vulnerable range.
ruby is vulnerable to Use-After-Free in versions 4.0.0 - 4.0.4.
Upgrade the ruby library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant