VYPR
High severity8.1NVD Advisory· Published Jul 31, 2026· Updated Sep 9, 2026

CVE-2026-53510

CVE-2026-53510

Description

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
savonRubyGems
>= 0.9.8, < 2.17.22.17.2

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.