
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-67989 is a polynomial-time Regular Expression Denial of Service (ReDoS) vulnerability in the crmne/ruby_llm Ruby AI framework, specifically in the Mistral model capability matching logic at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83. The flaw affects applications running on Ruby 3.1.x, where Ruby's regex engine lacks the match memoization optimization present in Ruby 3.2+. It was published on October 2, 2026, with a patch available the same day. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory).
The root cause is CWE-1333 (Inefficient Regular Expression Complexity). The vulnerable code in lib/ruby_llm/providers/mistral/capabilities.rb (around line 92) used regular expressions /voxtral.*tts/ and /voxtral.*transcribe/ to match Mistral model IDs. These patterns require the regex engine to rescan from every occurrence of voxtral in the string to find a matching suffix, resulting in quadratic (polynomial) time complexity when the model ID string contains many repetitions of voxtral without a matching suffix. On Ruby 3.1.x, which lacks match memoization, this causes excessive CPU consumption. The fix (commit dd3c848) replaces the backtracking-prone regexes with a String#index-based walk (voxtral_followed_by? helper method) that locates the first voxtral occurrence and then searches forward for the suffix, eliminating backtracking entirely (Github Commit, Github Advisory).
Successful exploitation causes a denial of service by consuming excessive CPU resources, potentially hanging or crashing the affected Ruby application. The impact is limited to availability — there is no confidentiality or integrity impact. Any service that passes attacker-controlled or externally sourced model ID strings through the Mistral capability matching logic on Ruby 3.1.x is at risk of becoming unresponsive (Github Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation as of the disclosure date. The vulnerability is automatable (no authentication or user interaction required) since an attacker only needs to supply a crafted model ID string containing many repetitions of voxtral without a matching suffix. The EPSS score is approximately 0.34%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 or earlier, running on Ruby 3.1.x, that accepts external input influencing Mistral model ID selection or processing.voxtral followed by a suffix that does not match tts or transcribe, e.g., "#{'voxtral' * 50_000}-nope". This causes the regex engine to backtrack quadratically.modalities_for or capabilities_for methods in lib/ruby_llm/providers/mistral/capabilities.rb./voxtral.*tts/ or /voxtral.*transcribe/ processes the input, causing the Ruby 3.1.x regex engine to consume excessive CPU time, resulting in application hang or crash (Github Commit, Github Advisory).voxtral) in API calls or configuration inputs.The fix is available in commit dd3c848 of the crmne/ruby_llm repository, which replaces the vulnerable regexes with a backtracking-free String#index-based helper method. Users should update to a version of ruby_llm that includes this commit. As an interim workaround, upgrading the Ruby runtime to version 3.2 or later mitigates the issue because Ruby 3.2 introduced match memoization that prevents the quadratic blowup. Additionally, implementing input validation and rate limiting on any endpoint that accepts model ID strings can reduce exposure (Github Commit, Github Advisory).
A brief mention of the CVE was noted on Mastodon via @thehackerwire shortly after disclosure. The Ruby security community indexed the advisory on RubySec. No significant vendor statements or major media coverage have been identified beyond the standard advisory publication (RubySec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."