CVE-2015-4412: Bson Project Bson

Critical severity, CVSS 9.8. EPSS: 4.7% chance of exploitation in the next 30 days.

BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.

Affected products

Published 2018-02-05. Last modified 2026-06-17.