top of page
perceptive_background_267k.jpg

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed…

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 21:02:18

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

CVE-2026-53510 affects Savon, a Ruby SOAP client library, across versions 0.9.8 through 2.17.2. The vulnerability exists in the Savon::Model .all_operations method, which interpolates attacker-controlled WSDL operation names into Ruby source code passed to module_eval. This allows an attacker who can supply a malicious WSDL to achieve arbitrary Ruby code execution within the application process. The flaw is classified as a code injection vulnerability stemming from unsafe use of eval with untrusted input. The issue has been patched in version 2.17.2 of the Savon gem. Users are strongly advised to upgrade to the fixed version immediately. References include the fix commit, the release tag, and the GitHub security advisory GHSA-mx5j-mp4f-g8jg.

Technical details

Mitigation steps:

Affected products:

Savon Ruby SOAP Client

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page