OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-67989

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the crmne/ruby_llm library, specifically in the Mistral model capability matching feature when running on Ruby 3.1.x. It introduces a polynomial-time regular expression denial-of-service condition, potentially allowing attackers to exhaust system resources and disrupt service availability. Organizations utilizing this library in their Ruby applications should prioritize remediation to mitigate the risk of service interruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67989
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x