A buffer overflow vulnerability (CVE-2026-27820) has been discovered in Ruby's Zlib::GzipReader. The flaw exists in the zstream_buffer_ungets function, which fails to ensure sufficient buffer capacity before shifting existing data, potentially leading to memory corruption. Ruby users are advised to update the zlib gem to

2m read time From ruby-lang.org
Post cover image
Table of contents
DetailsRecommended actionAffected versionsCredits

Sort: