Description
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Updated Code
AI Analysis

Impact

The ruby_llm library contains a regular expression routine that can be forced into a quadratic or worse runtime when given specially crafted input. This weakness enables an attacker to consume excessive CPU resources, resulting in a denial of service. The flaw is classified as a regular expression denial‑of‑service condition, corresponding to the general category of CWE-749.

Affected Systems

Any application that imports the ruby_llm gem and executes the Mistral capability matching code on Ruby 3.1.x is vulnerable. The issue appears in the code path introduced in commit fa6f279 and affects projects that use the providers/mistral/capabilities module for capability matching.

Risk and Exploitability

Exploitability requires that malicious input be processed by the vulnerable regex. No public exploits have been reported and no EPSS score is available; the vulnerability is not listed in the CISA KEV catalog. The risk level is therefore moderate, though untrusted input could trigger a DoS condition in an affected application.

Generated by OpenCVE AI on October 2, 2026 at 17:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the ruby_llm gem to a commit following dd3c848, which removes the vulnerable regex logic.
  • Validate or sanitize any input passed to the capability matching routine to avoid complex patterns that could trigger excessive backtracking.
  • Configure the Ruby regex engine with a timeout or employ a safer library for capability matching to limit execution time.

Generated by OpenCVE AI on October 2, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Title Polynomial‑time Regular Expression Denial of Service in Ruby‑LLM Mistral Capability Matching
Weaknesses CWE-749

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T19:09:36.496Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:51.247

Modified: 2026-10-02T18:51:09.530

Link: CVE-2026-67989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function