← Vulnerability feed

Vulnerability record · CVE-2008-4310 · published 9 December 2008

CVE-2008-4310: Ruby-lang ruby vulnerability

Ruby Lang · Ruby

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.

7.8 CVSS 2.0 High EPSS 14% · top 3.7% CWE-399 · CWE-399
7.8CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4310 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4124Ruby-lang ruby memory buffer overflow vulnerabilityHeap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute a…EPSS 3.9%10.0CVE-2008-2662Ruby-lang ruby vulnerabilityMultiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 befor…EPSS 4.3%10.0CVE-2008-2663Ruby-lang ruby integer overflow vulnerabilityMultiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before…EPSS 4.5%9.8CVE-2016-2338Ruby-lang ruby out-of-bounds write vulnerabilityAn exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function he…EPSS 4.7%9.8CVE-2022-28738Ruby-lang ruby double free vulnerabilityA double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste…EPSS 2.9%9.8CVE-2011-4121Ruby-lang ruby inadequate encryption strength vulnerabilityThe OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private…EPSS 2.5%9.8CVE-2018-16395Ruby-lang openssl vulnerabilityAn issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When tw…EPSS 11%9.8CVE-2017-17790Ruby-lang ruby injection vulnerabilityThe lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by…EPSS 5.9%

Source: NIST National Vulnerability Database (record CVE-2008-4310), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.