CVE-2014-9490: Getsentry Raven-Ruby

Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.

The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.

Affected products

  • Getsentry Raven-Ruby: up to and including 0.12.1

Published 2015-01-20. Last modified 2026-06-17.