CVE-2014-6438: Ruby-Lang Ruby

High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.

The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.

Affected products

Published 2017-09-06. Last modified 2026-06-17.