GHSA-jxhc-q857-3j6g · Severity: high · Ecosystem: rubygems — Regular Expression Denial of Service in Addressable templates
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected. The vulnerability is patched in version 2.8.0. As a workaround, only create Template objects from trusted sources that have been validated not to produce catastrophic backtracking.
Conclusion & alert: CVE-2021-32740 is rated Moderate Risk (61.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.53%). Core evidence: EPSS rose +1.64% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-03 | 0.89% | 2.53% | +1.64% |
| 2 | 2026-01-27 | 0.50% | 0.89% | +0.39% |
| 3 | 2025-11-21 | — | 0.50% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-jxhc-q857-3j6g · Severity: high · Ecosystem: rubygems — Regular Expression Denial of Service in Addressable templates
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2021-32740: 1 source package rows (ruby-addressable); 7 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2021-32740 |
debian
|
not yet assigned | CVE-2021-32740 not yet assigned priority: Debian including 1 source packages (ruby-addressable), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-32740 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-32740 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2021-32740/ |
ubuntu
|
low | CVE-2021-32740 low priority: Ubuntu including 1 source packages (ruby-addressable), 16 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 9, needs-triage 3, ignored 2, DNE 1, released 1. | https://ubuntu.com/security/CVE-2021-32740 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| addressable_project | addressable | >= 2.3.0, < 2.8.0 | cpe:2.3:a:addressable_project:addressable:*:*:*:*:*:ruby:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |