CRITICALRubyGems →
Savon::Model evaluates WSDL operation names as Ruby source
Savon::Model evaluates WSDL operation names as Ruby source
Affected packages
- savon— 0.9.8 → 2.17.2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.40%
- EPSS percentile
- 32.4%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 32%.
Sources
- https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg
- https://github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/savon/CVE-2026-53510.yml
- https://github.com/savonrb/savon
- https://github.com/savonrb/savon/releases/tag/v2.17.2
- https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-53510
Structured record: https://osv.dev/vulnerability/GHSA-mx5j-mp4f-g8jg
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta