VYPR
High severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026

Savon::Model evaluates WSDL operation names as Ruby source

CVE-2026-53510

Description

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
savonRubyGems
>= 0.9.8, < 2.17.22.17.2

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.