CVE-2026-67989: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-67989 is a polynomial-time Regular Expression Denial of Service (ReDoS) vulnerability in the crmne/ruby_llm Ruby AI framework, specifically in the Mistral model capability matching logic at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83. The flaw affects applications running on Ruby 3.1.x, where Ruby's regex engine lacks the match memoization optimization present in Ruby 3.2+. It was published on October 2, 2026, with a patch available the same day. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory).

Technical details

The root cause is CWE-1333 (Inefficient Regular Expression Complexity). The vulnerable code in lib/ruby_llm/providers/mistral/capabilities.rb (around line 92) used regular expressions /voxtral.*tts/ and /voxtral.*transcribe/ to match Mistral model IDs. These patterns require the regex engine to rescan from every occurrence of voxtral in the string to find a matching suffix, resulting in quadratic (polynomial) time complexity when the model ID string contains many repetitions of voxtral without a matching suffix. On Ruby 3.1.x, which lacks match memoization, this causes excessive CPU consumption. The fix (commit dd3c848) replaces the backtracking-prone regexes with a String#index-based walk (voxtral_followed_by? helper method) that locates the first voxtral occurrence and then searches forward for the suffix, eliminating backtracking entirely (Github Commit, Github Advisory).

Impact

Successful exploitation causes a denial of service by consuming excessive CPU resources, potentially hanging or crashing the affected Ruby application. The impact is limited to availability — there is no confidentiality or integrity impact. Any service that passes attacker-controlled or externally sourced model ID strings through the Mistral capability matching logic on Ruby 3.1.x is at risk of becoming unresponsive (Github Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation as of the disclosure date. The vulnerability is automatable (no authentication or user interaction required) since an attacker only needs to supply a crafted model ID string containing many repetitions of voxtral without a matching suffix. The EPSS score is approximately 0.34%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate a Ruby application using crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 or earlier, running on Ruby 3.1.x, that accepts external input influencing Mistral model ID selection or processing.
  2. Craft malicious model ID: Construct a string consisting of many repetitions of voxtral followed by a suffix that does not match tts or transcribe, e.g., "#{'voxtral' * 50_000}-nope". This causes the regex engine to backtrack quadratically.
  3. Submit payload: Supply the crafted model ID string to any application endpoint or API that triggers the modalities_for or capabilities_for methods in lib/ruby_llm/providers/mistral/capabilities.rb.
  4. Trigger ReDoS: The vulnerable regex /voxtral.*tts/ or /voxtral.*transcribe/ processes the input, causing the Ruby 3.1.x regex engine to consume excessive CPU time, resulting in application hang or crash (Github Commit, Github Advisory).

Indicators of compromise

  • Logs: Unusually long request processing times or timeouts in application logs associated with Mistral model capability lookups; Ruby process CPU usage spiking to 100% for extended periods.
  • Process: Ruby worker processes consuming near-maximum CPU for prolonged durations without completing requests; application threads or Fiber workers becoming unresponsive.
  • Network: Repeated requests containing abnormally long model ID strings (e.g., strings with thousands of characters repeating voxtral) in API calls or configuration inputs.

Mitigation and workarounds

The fix is available in commit dd3c848 of the crmne/ruby_llm repository, which replaces the vulnerable regexes with a backtracking-free String#index-based helper method. Users should update to a version of ruby_llm that includes this commit. As an interim workaround, upgrading the Ruby runtime to version 3.2 or later mitigates the issue because Ruby 3.2 introduced match memoization that prevents the quadratic blowup. Additionally, implementing input validation and rate limiting on any endpoint that accepts model ID strings can reduce exposure (Github Commit, Github Advisory).

Community reactions

A brief mention of the CVE was noted on Mastodon via @thehackerwire shortly after disclosure. The Ruby security community indexed the advisory on RubySec. No significant vendor statements or major media coverage have been identified beyond the standard advisory publication (RubySec).

Additional resources


Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management