What is CVE-2026-53510?
CVE-2026-53510 is a critical vulnerability in the Savon Ruby SOAP client affecting versions 0.9.8 to 2.17.2, where the `Savon::Model` `all_operations` method interpolates attacker-controlled WSDL operation names into Ruby source passed to `module_eval`, enabling remote code execution. Users should immediately upgrade to version 2.17.2 to mitigate the issue.
Azərbaycanca: CVE-2026-53510, Ruby SOAP client olan Savon kitabxanasında aşkarlanmış kritik boşluqdur. 0.9.8-dən 2.17.2 versiyasına qədər,`Savon::Model`-in `all_operations` metodu hücumçunun idarə etdiyi WSDL əməliyyat adlarını Ruby koduna daxil edib `module_eval` vasitəsilə icra etməyə imkan verir ki, bu da serverdə kod icrasına səbəb ola bilər. Təhlükəsizlik üçün dərhal 2.17.2 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Savon are affected by CVE-2026-53510?
All versions of the Savon library from 0.9.8 up to 2.17.2 are affected by CVE-2026-53510.
How can the CVE-2026-53510 vulnerability be mitigated?
To mitigate the vulnerability, it is recommended to immediately upgrade the Savon library to version 2.17.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.