CVE-2026-41316

Aliases:SUSE-SU-2026:3556-1RHSA-2026:18030RHSA-2026:18039RHSA-2026:18065RHSA-2026:20614RHSA-2026:20670RHSA-2026:26312RHSA-2026:26655RHSA-2026:33478DEBIAN-CVE-2026-41316CGA-3cx9-fxh7-2rr8CGA-3xpq-5h4x-x3cxCGA-459q-g5mf-92f5CGA-48w3-h4c5-f7p3CGA-4q38-j2hr-8ffwCGA-5x87-fvfp-q336CGA-69hq-6vxq-jfx6CGA-6q4w-vp22-c69pCGA-6r84-crg3-rfghCGA-6rrv-vj2f-vcmcCGA-6x4x-wqgh-6wgpCGA-7ccr-rrvr-2wgqCGA-826w-9m95-2gwvCGA-8rc8-jc3v-rvgqCGA-9jm8-h2fj-pm3gCGA-c6hj-59rf-78mwCGA-cgxw-qvg6-gx3vCGA-cjgh-gmp2-85phCGA-cw7f-cp35-fpppCGA-hv46-v8xp-mcfjCGA-p7vh-j2f4-h2xwCGA-pw8q-hwfh-394gCGA-2gg9-9w8g-p32xCGA-3598-v72j-q8grCGA-3c9w-mrgm-f75pCGA-3p69-2x6j-53mqCGA-3r58-vmcc-x3rmCGA-47x3-768q-h47gCGA-4cwg-jjmx-98q6CGA-4v77-3375-546qCGA-538c-2w4v-xg9cCGA-6465-48hr-r5pjCGA-6hxp-qvm2-24hjCGA-85p2-m5mm-rrpwCGA-89rj-fcf7-fm63CGA-8gpf-gjjh-mww2CGA-8gxh-rrj5-6xvfCGA-8xqm-jv94-h3wpCGA-92p9-583r-fq2jCGA-9j43-r4x4-vfcpCGA-9pwh-c65p-c64rCGA-9rx9-m75g-vpvwCGA-f557-j3gr-q246CGA-fhw7-vx6j-c8rqCGA-fx27-jv86-7c89CGA-g8pj-xh23-5r7mCGA-gvhg-mr4h-hfv6CGA-j324-hpvp-jjxwCGA-j4wq-vp25-8r96CGA-jh7f-8g6j-jqfqCGA-jqvc-rm6g-2p2wCGA-m5cv-3w96-jf5hCGA-m8qx-c7hg-2fmmCGA-mg68-qhv7-r8c3CGA-p2r4-97rq-9h8cCGA-pj5c-8mww-g72cCGA-pq5h-xhvh-98hfCGA-pqch-c99c-wj9xCGA-prq6-cq4v-xxhcCGA-q2cc-25vr-j63vCGA-q836-86c4-4mj7CGA-r866-2cg2-6hw3CGA-rg86-pgh8-w24xCGA-rvh4-2cpw-3994CGA-v455-3pwp-357xCGA-vqwp-qrp3-j4fcCGA-wcwq-fcq5-f64mCGA-wg88-42m8-pwqrCGA-wh82-j676-rg4mCGA-wjm6-jpfg-cpgjCGA-wqxq-wwrj-438mCGA-x64h-c4xg-9mfpCGA-xc2w-6g6x-hmcfCGA-xfvp-r6qx-hh9p
Deferred
Published: 24 Apr 2026, 02:35
Last modified:24 Aug 2026, 12:06

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
1.13% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Apr 2026, 02:35
Published
Vulnerability first disclosed
24 Aug 2026, 12:06
Last Modified
Vulnerability information updated

Description

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 1.13% Percentile: 65%

Techniques & Countermeasures

  • CWE-693Protection Mechanism Failure

    The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • chainguardjruby-10.1

    < 10.1.1.0-r0

  • chainguardjruby-9.4

    < 9.4.15.0-r0

  • chainguardlogstash-8.19

    < 8.19.19-r0

  • chainguardlogstash-8.19-iamguarded-compat

    < 8.19.19-r0

  • chainguardlogstash-8.19-with-output-opensearch

    < 8.19.19-r0

  • chainguardlogstash-9.0

    all

  • chainguardlogstash-9.0-iamguarded-compat

    all

  • chainguardlogstash-9.0-with-output-opensearch

    all

  • chainguardlogstash-9.1

    all

  • chainguardlogstash-9.1-bitnami-compat

    all

  • chainguardlogstash-9.1-iamguarded-compat

    all

  • chainguardlogstash-9.1-with-output-opensearch

    all

  • chainguardlogstash-9.2

    all

  • chainguardlogstash-9.2-iamguarded-compat

    all

  • chainguardlogstash-9.2-with-output-opensearch

    all

  • chainguardlogstash-9.3

    < 9.3.4-r2

  • chainguardlogstash-9.3-iamguarded-compat

    < 9.3.4-r2

  • chainguardlogstash-9.3-with-output-opensearch

    all

  • chainguardlogstash-fips-9.3

    < 9.3.4-r0

  • chainguardlogstash-fips-9.3-iamguarded-compat

    < 9.3.4-r0

  • chainguardruby-3.2

    all

  • chainguardruby-3.3

    < 3.3.12-r0

  • chainguardruby-3.4

    < 3.4.10-r0

  • chainguardruby-4.0

    < 4.0.3-r0

  • chainguardruby3.2-rails-7.2

    < 7.2.3.1-r2

  • chainguardruby3.2-rails-8.0

    < 8.0.5-r1

  • chainguardruby3.2-rails-8.1

    < 8.1.3-r3

  • chainguardruby3.3-rails-7.2

    < 7.2.3.1-r3

  • chainguardruby3.3-rails-8.0

    < 8.0.5-r2

  • chainguardruby3.3-rails-8.1

    < 8.1.3-r4

  • chainguardruby3.4-rails-7.2

    < 7.2.3.1-r3

  • chainguardruby3.4-rails-8.0

    < 8.0.5-r2

  • chainguardruby3.4-rails-8.1

    < 8.1.3-r3

  • chainguardruby4.0-rails-7.2

    < 7.2.3.1-r3

  • chainguardruby4.0-rails-8.0

    < 8.0.5-r2

  • chainguardruby4.0-rails-8.1

    < 8.1.3-r4

  • chainguardtruffleruby

    < 34.0.1-r2

  • wolfijruby-10.1

    < 10.1.1.0-r0

  • wolfijruby-9.4

    < 9.4.15.0-r0

  • wolfilogstash-9.3

    < 9.3.4-r2

  • wolfilogstash-9.3-iamguarded-compat

    < 9.3.4-r2

  • wolfilogstash-9.3-with-output-opensearch

    all

  • wolfiruby-3.2

    all

  • wolfiruby-3.3

    < 3.3.12-r0

  • wolfiruby-3.4

    < 3.4.10-r0

  • wolfiruby-4.0

    < 4.0.3-r0

  • wolfiruby3.2-rails-8.1

    < 8.1.3-r3

  • wolfiruby3.3-rails-8.1

    < 8.1.3-r4

  • wolfiruby3.4-rails-8.1

    < 8.1.3-r3

  • wolfiruby4.0-rails-8.1

    < 8.1.3-r4

Showing first 50 affected entries in server-rendered view.

References (33)