CVE-2023-28755: Debian Linux

Medium severity, CVSS 5.3. EPSS: 2.6% chance of exploitation in the next 30 days.

A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 36 only; version 37 only; version 38 only
  • Ruby-Lang Uri: up to and including 0.10.0; version 0.10.1 only; version 0.11.0 only; version 0.12.0 only

Published 2023-03-31. Last modified 2026-06-17.