High severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source
CVE-2026-53510
Description
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
savonRubyGems | >= 0.9.8, < 2.17.2 | 2.17.2 |
Affected products
2- Range: <=2.17.2
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-mx5j-mp4f-g8jgghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/savon/CVE-2026-53510.ymlghsaWEB
- github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9ghsax_refsource_MISCWEB
- github.com/savonrb/savon/releases/tag/v2.17.2ghsax_refsource_MISCWEB
- github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jgghsax_refsource_CONFIRMWEB
- www.cve.org/CVERecord/SearchResultsghsaWEB
News mentions
0No linked articles in our index yet.