jruby-openssl
JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library.
Activity
- Latest release
- 1w ago
- Total releases
- 97
- Cadence
- ~2 months
- Last 12 months
- 7
Details
- License
- unknown OR GPL-2.0 OR LGPL-2.1
- First release
- Mar 01, 2007
| Version | Released | |
|---|---|---|
0.19.1
patch
|
0.19.1
patch
|
|
0.19.0
minor
|
0.19.0
minor
|
|
0.16.2
patch
|
0.16.2
patch
|
|
0.16.1
patch
|
0.16.1
patch
|
|
0.16.0
minor
|
0.16.0
minor
|
|
0.15.7
patch
|
0.15.7
patch
|
|
0.15.6
patch
|
0.15.6
patch
|
|
0.15.5
patch
|
0.15.5
patch
|
|
0.15.4
patch
|
0.15.4
patch
|
|
0.15.4.pre1
pre
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.4.pre1
pre
|
|
0.15.3
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.3
patch
|
|
0.15.2
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.2
patch
|
|
0.15.1
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.1
patch
|
|
0.15.0
minor
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.0
minor
|
|
0.14.6
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.6
patch
|
|
0.14.5
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.5
patch
|
|
0.14.4
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.4
patch
|
|
0.14.3
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.3
patch
|
|
0.14.2
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.2
patch
|
|
0.14.1
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.1
patch
|
|
0.14.1.cr2
pre
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.1.cr2
pre
|
|
0.14.0
minor
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.0
minor
|
|
0.13.0
minor
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.13.0
minor
|
|
0.12.2
patch
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.12.2
patch
|
|
0.12.1
minor
1 CVE
CVE-2025-46551
GHSA-72qj-48g4-5xgx
May 07, 2025
JRuby-OpenSSL has hostname verification disabled by default
Medium
Network
Low
Low
None
SummaryWhen verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present any valid cert for a completely different domain they own, and JRuby wouldn't complain. Detailsn/a PoCAn example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with
ImpactAnybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely Affected versions
0.12.1
0.12.2
0.13.0
0.14.0
0.14.1
0.14.1.cr2
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
+ 4 more Show less
0.15.1
0.15.2
0.15.3
0.15.4.pre1
Fixed in
0.15.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.12.1
minor
|
|
0.11.0
minor
|
0.11.0
minor
|
|
0.11.0.cr1
pre
|
0.11.0.cr1
pre
|
|
0.10.7
patch
|
0.10.7
patch
|
|
0.10.5
patch
|
0.10.5
patch
|
|
0.10.3
patch
|
0.10.3
patch
Dependencies (3)
|
|
0.10.4
patch
|
0.10.4
patch
Dependencies (3)
|
|
0.10.2
patch
|
0.10.2
patch
Dependencies (3)
|
|
0.10.1
patch
|
0.10.1
patch
Dependencies (3)
|
|
0.10.0
minor
|
0.10.0
minor
Dependencies (3)
|
|
0.9.21
patch
|
0.9.21
patch
Dependencies (3)
|
|
0.9.20
patch
|
0.9.20
patch
Dependencies (3)
|
|
0.9.19
patch
|
0.9.19
patch
Dependencies (3)
|
|
0.9.18
patch
|
0.9.18
patch
Dependencies (3)
|
|
0.9.17
patch
|
0.9.17
patch
Dependencies (3)
|
|
0.9.16
patch
|
0.9.16
patch
Dependencies (3)
|
|
0.9.15
patch
|
0.9.15
patch
Dependencies (3)
|
|
0.9.14
patch
|
0.9.14
patch
Dependencies (3)
|
|
0.9.13
patch
|
0.9.13
patch
Dependencies (3)
|
|
0.9.12
patch
|
0.9.12
patch
Dependencies (3)
|
|
0.9.11
patch
|
0.9.11
patch
Dependencies (3)
|
|
0.9.10
patch
|
0.9.10
patch
Dependencies (3)
|
|
0.9.9
patch
|
0.9.9
patch
Dependencies (3)
|
|
0.9.8
patch
|
0.9.8
patch
Dependencies (3)
|
|
0.9.7
patch
|
0.9.7
patch
Dependencies (3)
|
|
0.9.6
patch
|
0.9.6
patch
Dependencies (2)
|