CVE-2023-28756: Debian Linux
Medium severity, CVSS 5.3. EPSS: 2.5% chance of exploitation in the next 30 days.
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 36 only; version 37 only; version 38 only
- Ruby-Lang Ruby: up to and including 2.7.7
- Ruby-Lang Time: version 0.1.0 only; version 0.2.1 only
Published 2023-03-31. Last modified 2026-06-17.