Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. This is due to how Ruby reads the Manifest of Gem files when using Gem::Specification.from_yaml. from_yaml makes use of SafeYAML.load which allows YAML aliases inside the YAML-based metadata of a gem. YAML aliases allow for Denial of Service attacks with so-called `YAML-bombs` (comparable to Billion laughs attacks). This was patched. There is is no action required by users. This issue is also tracked as GHSL-2024-001 and was discovered by the GitHub security lab.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp10 | — | Upgrade rubyUpgrade ruby-helpUpgrade ruby-irb | Oct 8, 2024 | May 29, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade ruby-helpUpgrade rubyUpgrade ruby-irb | Oct 9, 2024 | May 29, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade ruby-helpUpgrade ruby-irbUpgrade ruby | Oct 9, 2024 | May 29, 2024 |
| Suse | — | Upgrade ruby2.5-stdlibUpgrade ruby2.5-docUpgrade libruby2_5-2_5Upgrade ruby2.5Upgrade ruby2.5-doc-riUpgrade ruby2.5-devel-extraUpgrade ruby2.5-devel | Dec 5, 2025 | Aug 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub