CVE-2026-53510
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| savonrb | savon | >= 0.9.8, < 2.17.2 | affected |
Weaknesses
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg
- https://github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9
- https://github.com/savonrb/savon/releases/tag/v2.17.2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.