iodine
A fast HTTP / Websocket Server with built-in Pub/Sub support (with or without Redis), static file support and many other features, optimized for Ruby MRI on Linux / BSD / macOS / Windows
Activity
- Latest release
- 3mo ago
- Total releases
- 136
- Cadence
- ~15 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 17, 2015
| Version | Released | |
|---|---|---|
0.7.59
patch
| ||
0.7.58
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.57
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.56
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.55
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.54
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.53
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.52
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.51
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.50
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.49
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.48
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.47
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.46
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.45
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.44
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.43
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.42
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.41
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.40
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.39
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.38
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.37
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.36
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.35
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.34
patch
1 CVE
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.33
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.32
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.31
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.29
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.28
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.27
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.26
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.25
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.24
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.23
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.22
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.21
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.20
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.19
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.18
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.17
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.16
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.15
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.14
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.13
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.12
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.11
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.10
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
| ||
0.7.9
patch
2 CVEs
CVE-2026-41146
GHSA-2x79-gwq3-vxxm
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
Network
Low
None
None
Summary
The smallest reproducer found is DetailsThe vulnerable logic is in This parser is reached from real library entry points, not just the header in isolation:
Relevant flow:
The same logic exists in Why the
Examples that trigger the bug:
PoCEnvironment used for verification:
Minimal standalone programUse the normal HTTP stack. The following server calls
Save it as
Run:
Then in another terminal send one of these payloads:
Observed result on a vulnerable build:
Downstream impact in
|