High severity8.1NVD Advisory· Published Jul 31, 2026· Updated Sep 9, 2026
CVE-2026-53510
CVE-2026-53510
Description
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
savonRubyGems | >= 0.9.8, < 2.17.2 | 2.17.2 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-mx5j-mp4f-g8jgghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/savon/CVE-2026-53510.ymlghsaWEB
- github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9nvdWEB
- github.com/savonrb/savon/releases/tag/v2.17.2nvdWEB
- github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jgnvdWEB
- www.cve.org/CVERecord/SearchResultsghsaWEB
News mentions
0No linked articles in our index yet.