Impact
The ruby_llm library contains a regular expression routine that can be forced into a quadratic or worse runtime when given specially crafted input. This weakness enables an attacker to consume excessive CPU resources, resulting in a denial of service. The flaw is classified as a regular expression denial‑of‑service condition, corresponding to the general category of CWE-749.
Affected Systems
Any application that imports the ruby_llm gem and executes the Mistral capability matching code on Ruby 3.1.x is vulnerable. The issue appears in the code path introduced in commit fa6f279 and affects projects that use the providers/mistral/capabilities module for capability matching.
Risk and Exploitability
Exploitability requires that malicious input be processed by the vulnerable regex. No public exploits have been reported and no EPSS score is available; the vulnerability is not listed in the CISA KEV catalog. The risk level is therefore moderate, though untrusted input could trigger a DoS condition in an affected application.
OpenCVE Enrichment