CVE-2026-53510: Savonrb Savon

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.

Affected products

  • Savonrb Savon: from 0.9.8, before 2.17.2 (fixed in 2.17.2)

Published 2026-07-31. Last modified 2026-09-09.