cgi
Support for the Common Gateway Interface protocol.
Activity
- Latest release
- 2mo ago
- Total releases
- 26
- Cadence
- ~21 days
- Last 12 months
- 2
Details
- License
- unknown OR BSD-2-Clause
- First release
- Nov 06, 2019
| Version | Released | |
|---|---|---|
0.5.2
patch
| ||
0.5.1
patch
| ||
0.5.0
minor
| ||
0.5.0.beta2
pre
| ||
0.5.0.beta1
pre
| ||
0.3.7
patch
| ||
0.4.2
patch
| ||
0.4.2.beta1
pre
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.2.beta2
pre
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.5.1
patch
| ||
0.4.1
patch
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.6
patch
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.5
patch
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.2
patch
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.0.2
patch
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.4
patch
3 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.1.0.1
patch
3 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.3.3
patch
3 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.3.2
patch
3 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.1
patch
3 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.2.1
patch
3 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.3.0
minor
5 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2021-41819
GHSA-4vf4-qmvg-mh7h
BIT-ruby-2021-41819
BIT-ruby-min-2021-41819
Jan 21, 2022
Cookie Prefix Spoofing in CGI::Cookie.parse
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby. Affected versions
0.3.0
0.2.0
0.1.0
Fixed in
0.1.0.1
0.2.1
0.3.1
References
Updated Jan 27, 2025 · Source: OSV.dev
CVE-2021-41816
GHSA-5cqm-crxm-6qpv
Dec 14, 2021
Buffer overrun in CGI.escape_html
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A buffer overrun vulnerability was discovered in CGI.escape_html. This can lead to a buffer overflow when a user passes a very large string (> 700 MB) to CGI.escape_html on a platform where long type takes 4 bytes, typically, Windows. Affected versions
0.3.0
0.2.0
0.1.0
Fixed in
0.1.0.1
0.2.1
0.3.1
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.2.0
minor
5 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2021-41819
GHSA-4vf4-qmvg-mh7h
BIT-ruby-2021-41819
BIT-ruby-min-2021-41819
Jan 21, 2022
Cookie Prefix Spoofing in CGI::Cookie.parse
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby. Affected versions
0.3.0
0.2.0
0.1.0
Fixed in
0.1.0.1
0.2.1
0.3.1
References
Updated Jan 27, 2025 · Source: OSV.dev
CVE-2021-41816
GHSA-5cqm-crxm-6qpv
Dec 14, 2021
Buffer overrun in CGI.escape_html
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A buffer overrun vulnerability was discovered in CGI.escape_html. This can lead to a buffer overflow when a user passes a very large string (> 700 MB) to CGI.escape_html on a platform where long type takes 4 bytes, typically, Windows. Affected versions
0.3.0
0.2.0
0.1.0
Fixed in
0.1.0.1
0.2.1
0.3.1
References
Updated Aug 13, 2026 · Source: OSV.dev | ||
0.1.0
initial
5 CVEs
CVE-2025-27220
GHSA-mhwm-jh88-3gjf
Mar 03, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Medium
Network
High
None
None
There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem. DetailsThe regular expression used in This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27219
GHSA-gh9q-2xrm-x6qv
Mar 03, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Medium
Network
High
None
None
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem. DetailsCGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service. Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later. Affected versionscgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1. CreditsThanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability. Affected versions
0.1.0
0.1.0.1
0.1.0.2
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
+ 6 more Show less
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2.beta1
0.4.2.beta2
Fixed in
0.3.5.1
0.3.7
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-33621
GHSA-vc47-6rqg-c7f5
BIT-ruby-2021-33621
BIT-ruby-min-2021-33621
Nov 19, 2022
HTTP response splitting in CGI
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Ruby gem cgi.rb prior to versions 0.3.5, 0.2.2 and 0.1.0.2 allow HTTP header injection. If a CGI application using the CGI library inserts untrusted input into the HTTP response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. This issue has been patched in versions 0.3.5, 0.2.2 and 0.1.0.2. Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.2.0
0.2.1
0.1.0
0.1.0.1
Fixed in
0.1.0.2
0.2.2
0.3.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2021-41819
GHSA-4vf4-qmvg-mh7h
BIT-ruby-2021-41819
BIT-ruby-min-2021-41819
Jan 21, 2022
Cookie Prefix Spoofing in CGI::Cookie.parse
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem prior to versions 0.3.1, 0.2.1, 0.1.1, and 0.1.0.1 for Ruby. Affected versions
0.3.0
0.2.0
0.1.0
Fixed in
0.1.0.1
0.2.1
0.3.1
References
Updated Jan 27, 2025 · Source: OSV.dev
CVE-2021-41816
GHSA-5cqm-crxm-6qpv
Dec 14, 2021
Buffer overrun in CGI.escape_html
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A buffer overrun vulnerability was discovered in CGI.escape_html. This can lead to a buffer overflow when a user passes a very large string (> 700 MB) to CGI.escape_html on a platform where long type takes 4 bytes, typically, Windows. Affected versions
0.3.0
0.2.0
0.1.0
Fixed in
0.1.0.1
0.2.1
0.3.1
References
Updated Aug 13, 2026 · Source: OSV.dev |