[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2015-9096":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":37,"duplicate_of":9,"upstream":38,"downstream":39,"duplicates":58,"related":59,"reserved_at":9,"published_at":62,"modified_at":63,"state":64,"summary":65,"references_raw":73,"kevs":107,"epss":108,"epss_history":111,"metrics":369,"affected":380},"CVE-2015-9096","Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-93","Improper Neutralization of CRLF Sequences ('CRLF Injection')","The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.","weakness","Draft","Base",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-15","Command Delimiters",[],{"id":24,"name":25,"techniques":26},"CAPEC-81","Web Server Logs Tampering",[],[28],{"_key":29,"name":30,"source":31,"url":32,"maturity":33,"reliability_score":34,"verified":35,"type":9,"platforms":36,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_8E84CF846D91F74E","Exploit Reference (mbsd.jp)","reference","http://www.mbsd.jp/Whitepaper/smtpi.pdf","unknown",0.2,false,[],[],[],[40,42,44,46,48,50,52,54,56],{"_key":41},"SUSE-SU-2020:1570-1",{"_key":43},"DLA-1421-1",{"_key":45},"DSA-3966-1",{"_key":47},"MGASA-2017-0290",{"_key":49},"UBUNTU-CVE-2015-9096",{"_key":51},"USN-3365-1",{"_key":53},"RHSA-2026:7305",{"_key":55},"RHSA-2026:7307",{"_key":57},"RHSA-2026:8838",[],[60,61],{"_key":41},{"_key":47},"2017-06-12T20:00:00.000Z","2024-08-06T08:36:31.894Z","Modified",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":66,"epss_score":67,"severity":68,"severity_score":69,"severity_version":70,"severity_source":71,"severity_vector":72,"severity_status":64},"low",0.01592,"medium",6.1,"v3.0","nvd","CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",[74,81,87,93,98,103],{"url":75,"sources":76,"tags":78},"https://www.debian.org/security/2017/dsa-3966",[77,71],"cve.org",[79,80],"Vendor Advisory","X Refsource DEBIAN",{"url":82,"sources":83,"tags":84},"https://hackerone.com/reports/137631",[77,71],[85,86],"X Refsource MISC","Third Party Advisory",{"url":88,"sources":89,"tags":90},"https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html",[77,71],[91,92],"Mailing List","X Refsource MLIST",{"url":94,"sources":95,"tags":96},"https://github.com/rubysec/ruby-advisory-db/issues/215",[77,71],[85,97,86],"Issue Tracking",{"url":99,"sources":100,"tags":101},"https://github.com/ruby/ruby/commit/0827a7e52ba3d957a634b063bf5a391239b9ffee",[77,71],[85,102,86],"Patch",{"url":32,"sources":104,"tags":105},[77,71],[85,106,86],"Exploit",[],{"date":109,"score":67,"percentile":110},"2026-06-04",0.81997,[112,115,118,121,124,127,130,133,136,139,142,145,148,150,153,156,159,162,165,168,171,173,176,179,182,185,188,191,194,197,199,202,205,208,210,213,216,219,222,225,228,231,234,237,240,243,246,249,252,255,257,260,263,265,269,272,275,278,281,284,287,290,293,296,299,301,304,306,309,311,313,315,318,321,324,327,330,333,336,339,342,345,348,351,353,356,359,361,364,366],{"date":113,"score":67,"percentile":114},"2025-11-04",0.8104,{"date":116,"score":67,"percentile":117},"2025-11-05",0.81041,{"date":119,"score":67,"percentile":120},"2025-11-06",0.81043,{"date":122,"score":67,"percentile":123},"2025-11-07",0.81053,{"date":125,"score":67,"percentile":126},"2025-11-08",0.81061,{"date":128,"score":67,"percentile":129},"2025-11-09",0.81057,{"date":131,"score":67,"percentile":132},"2025-11-10",0.81051,{"date":134,"score":67,"percentile":135},"2025-11-11",0.81058,{"date":137,"score":67,"percentile":138},"2025-11-12",0.8107,{"date":140,"score":67,"percentile":141},"2025-11-13",0.81077,{"date":143,"score":67,"percentile":144},"2025-11-14",0.81082,{"date":146,"score":67,"percentile":147},"2025-11-15",0.81078,{"date":149,"score":67,"percentile":147},"2025-11-16",{"date":151,"score":67,"percentile":152},"2025-11-17",0.81075,{"date":154,"score":67,"percentile":155},"2025-11-18",0.80135,{"date":157,"score":67,"percentile":158},"2025-11-19",0.8014,{"date":160,"score":67,"percentile":161},"2025-11-20",0.80147,{"date":163,"score":67,"percentile":164},"2025-11-21",0.81091,{"date":166,"score":67,"percentile":167},"2025-11-22",0.81095,{"date":169,"score":67,"percentile":170},"2025-11-23",0.81087,{"date":172,"score":67,"percentile":170},"2025-11-24",{"date":174,"score":67,"percentile":175},"2025-11-25",0.81092,{"date":177,"score":67,"percentile":178},"2025-11-26",0.81094,{"date":180,"score":67,"percentile":181},"2025-11-27",0.811,{"date":183,"score":67,"percentile":184},"2025-11-28",0.8109,{"date":186,"score":67,"percentile":187},"2025-11-29",0.81097,{"date":189,"score":67,"percentile":190},"2025-11-30",0.81101,{"date":192,"score":67,"percentile":193},"2025-12-01",0.81185,{"date":195,"score":67,"percentile":196},"2025-12-02",0.81188,{"date":198,"score":67,"percentile":196},"2025-12-03",{"date":200,"score":67,"percentile":201},"2025-12-04",0.81104,{"date":203,"score":67,"percentile":204},"2025-12-05",0.81111,{"date":206,"score":67,"percentile":207},"2025-12-06",0.81113,{"date":209,"score":67,"percentile":207},"2025-12-07",{"date":211,"score":67,"percentile":212},"2025-12-08",0.81114,{"date":214,"score":67,"percentile":215},"2025-12-09",0.81131,{"date":217,"score":67,"percentile":218},"2025-12-10",0.81157,{"date":220,"score":67,"percentile":221},"2025-12-11",0.81167,{"date":223,"score":67,"percentile":224},"2025-12-12",0.81181,{"date":226,"score":67,"percentile":227},"2025-12-13",0.8118,{"date":229,"score":67,"percentile":230},"2025-12-14",0.81176,{"date":232,"score":67,"percentile":233},"2025-12-15",0.81173,{"date":235,"score":67,"percentile":236},"2025-12-16",0.81184,{"date":238,"score":67,"percentile":239},"2025-12-17",0.81193,{"date":241,"score":67,"percentile":242},"2025-12-18",0.81211,{"date":244,"score":67,"percentile":245},"2025-12-19",0.81218,{"date":247,"score":67,"percentile":248},"2025-12-20",0.81212,{"date":250,"score":67,"percentile":251},"2025-12-21",0.81208,{"date":253,"score":67,"percentile":254},"2025-12-22",0.81205,{"date":256,"score":67,"percentile":251},"2025-12-23",{"date":258,"score":67,"percentile":259},"2025-12-24",0.81221,{"date":261,"score":67,"percentile":262},"2025-12-25",0.81237,{"date":264,"score":67,"percentile":262},"2025-12-26",{"date":266,"score":267,"percentile":268},"2025-12-27",0.01099,0.77577,{"date":270,"score":67,"percentile":271},"2025-12-28",0.81224,{"date":273,"score":67,"percentile":274},"2025-12-29",0.8122,{"date":276,"score":67,"percentile":277},"2025-12-30",0.81226,{"date":279,"score":67,"percentile":280},"2025-12-31",0.8124,{"date":282,"score":67,"percentile":283},"2026-01-01",0.81317,{"date":285,"score":67,"percentile":286},"2026-01-02",0.81309,{"date":288,"score":67,"percentile":289},"2026-01-03",0.81305,{"date":291,"score":67,"percentile":292},"2026-01-04",0.81216,{"date":294,"score":67,"percentile":295},"2026-01-05",0.8121,{"date":297,"score":67,"percentile":298},"2026-01-06",0.81213,{"date":300,"score":67,"percentile":292},"2026-01-07",{"date":302,"score":67,"percentile":303},"2026-01-08",0.81225,{"date":305,"score":67,"percentile":277},"2026-01-09",{"date":307,"score":67,"percentile":308},"2026-01-10",0.81227,{"date":310,"score":67,"percentile":274},"2026-01-11",{"date":312,"score":67,"percentile":248},"2026-01-12",{"date":314,"score":67,"percentile":295},"2026-01-13",{"date":316,"score":67,"percentile":317},"2026-01-14",0.8123,{"date":319,"score":67,"percentile":320},"2026-01-15",0.81233,{"date":322,"score":67,"percentile":323},"2026-01-16",0.81243,{"date":325,"score":67,"percentile":326},"2026-01-17",0.81249,{"date":328,"score":67,"percentile":329},"2026-01-18",0.81242,{"date":331,"score":67,"percentile":332},"2026-01-19",0.81235,{"date":334,"score":67,"percentile":335},"2026-01-20",0.81238,{"date":337,"score":67,"percentile":338},"2026-01-21",0.81245,{"date":340,"score":67,"percentile":341},"2026-01-22",0.81253,{"date":343,"score":67,"percentile":344},"2026-01-23",0.81278,{"date":346,"score":67,"percentile":347},"2026-01-24",0.81285,{"date":349,"score":67,"percentile":350},"2026-01-25",0.81281,{"date":352,"score":67,"percentile":350},"2026-01-26",{"date":354,"score":67,"percentile":355},"2026-01-27",0.81283,{"date":357,"score":67,"percentile":358},"2026-01-28",0.81282,{"date":360,"score":67,"percentile":344},"2026-01-29",{"date":362,"score":67,"percentile":363},"2026-01-30",0.81277,{"date":365,"score":67,"percentile":347},"2026-01-31",{"date":367,"score":67,"percentile":368},"2026-02-01",0.8137,[370],{"source":71,"cvss_v2_0":371,"cvss_v3_0":376,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":372,"baseSeverity":9,"vectorString":373,"impactScore":374,"exploitabilityScore":375},4.3,"AV:N/AC:M/Au:N/C:N/I:P/A:N",2.9,8.6,{"baseScore":69,"baseSeverity":377,"vectorString":72,"impactScore":378,"exploitabilityScore":379},"MEDIUM",4.5,7.2,[381],{"ecosystem":9,"name":382,"vendor":383,"product":382,"cpe_part":384,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":385},"ruby","ruby-lang","a",[386],{"version":387,"is_range":388,"range_type":389,"version_start":9,"version_start_type":9,"version_end":390,"version_end_type":391,"fixed_in":9},"lte2.4.0",true,"cpe","2.4.0","including"]