CVE-2011-4815: Ruby-Lang Ruby

High severity, CVSS 7.8. EPSS: 4.1% chance of exploitation in the next 30 days.

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Affected products

  • Ruby-Lang Ruby: up to and including 1.8.7-p352; version 1.8.7-p299 only; version 1.8.7-p302 only; version 1.8.7-p330 only; version 1.8.7-p334 only

Published 2011-12-30. Last modified 2026-06-16.