CVE-2025-27788

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 12, 2025
Updated: Apr 2, 2025
CWE ID 125

Summary

CVE-2025-27788 is a vulnerability affecting the JSON implementation for Ruby, versions 2.10.0 to 2.10.1. A maliciously crafted JSON document can lead to an out-of-bound read, causing a crash. Versions before 2.10.0 are not susceptible to this issue. Currently, no workarounds are available, and users should upgrade to version 2.10.2 for a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share