PatchSiren

savonrb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH savonrb CVE published 2026-07-31

CVE-2026-53510

The Savon Ruby SOAP client vulnerability (CVE-2026-53510) allows Ruby code execution via attacker-controlled WSDL operation names in versions between 0.9.8 and 2.17.2. This issue is fixed in version 2.17.2. Users of Savon Ruby SOAP client should prioritize upgrading to version 2.17.2 or later to mitigate this vulnerability. The vulnerability can have a significant impact on the security of affected system [truncated]