/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2021-41816

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2021-41816

Severity

9.8

Critical

CVSS V3

Description

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing