bcrypt-ruby_project CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

bcrypt-ruby_project 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to bcrypt-ruby_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-33306 bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby (`BCrypt.java`) computes the key-strengthening round count as a signed 32-bit integer. When `cost=31` (the maximum allowed by the gem), signed integer overflow c [email protected] 4.5 0.23% 2026-03-24 2026-03-30
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence