CVE-2011-4815

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Published: 2011-12-30 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2011-4815 is rated High Risk (65.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.25%). Core evidence: EPSS rose +2.83% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2011-4815

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.41% 4.25% +2.83%
2 2026-06-04 0.95% 1.41% +0.46%
3 2026-06-03 0.95%

Full EPSS history (22 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2011-4815

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.8 2.0 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 6.9 [email protected]

Weakness enumeration for CVE-2011-4815

OS Trackers for CVE-2011-4815

vendor priority summary link
gentoo normal CVE-2011-4815: 1 GLSA(s) (201412-27), 1 atom(s) (dev-lang/ruby); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2011-4815
redhat medium https://access.redhat.com/security/cve/CVE-2011-4815
ubuntu medium CVE-2011-4815 medium priority: Ubuntu including 3 source packages (ruby1.8, ruby1.9, ruby1.9.1), 18 status rows across 6 suites (hardy, lucid, maverick, natty, oneiric, upstream): not-affected 8, released 5, DNE 4, ignored 1. https://ubuntu.com/security/CVE-2011-4815

Affected software / configurations for CVE-2011-4815

Vendor Product Version Raw CPE
ruby-lang ruby <= 1.8.7-p352 cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
ruby-lang ruby 1.8.7-p299 cpe:2.3:a:ruby-lang:ruby:1.8.7-p299:*:*:*:*:*:*:*
ruby-lang ruby 1.8.7-p302 cpe:2.3:a:ruby-lang:ruby:1.8.7-p302:*:*:*:*:*:*:*
ruby-lang ruby 1.8.7-p330 cpe:2.3:a:ruby-lang:ruby:1.8.7-p330:*:*:*:*:*:*:*
ruby-lang ruby 1.8.7-p334 cpe:2.3:a:ruby-lang:ruby:1.8.7-p334:*:*:*:*:*:*:*

References for CVE-2011-4815

URL Tags
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/391606
http://jvn.jp/en/jp/JVN90615481/index.html
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-000066.html
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
http://rhn.redhat.com/errata/RHSA-2012-0069.html
http://rhn.redhat.com/errata/RHSA-2012-0070.html
http://secunia.com/advisories/47405
http://secunia.com/advisories/47822
http://support.apple.com/kb/HT5281
http://www.kb.cert.org/vuls/id/903934 US Government Resource
http://www.nruns.com/_downloads/advisory28122011.pdf
http://www.ocert.org/advisories/ocert-2011-003.html
http://www.ruby-lang.org/en/news/2011/12/28/denial-of-service-attack-was-found-for-rubys-hash-algorithm/
http://www.securitytracker.com/id?1026474
https://exchange.xforce.ibmcloud.com/vulnerabilities/72020
cvelogic Threat Intelligence