CVE-2026-67989

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

  • Published Oct 2, 2026
  • CVSS 7.5 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-67989 at the National Vulnerability Database