CVE-2026-53510

HIGH

Savon::Model evaluates WSDL operation names as Ruby source

Title source: cna
STIX 2.1

Description

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.

Scores

CVSS v3 8.1
EPSS 0.0040
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
rubygems/savon 0.9.8 - 2.17.2RubyGems
savonrb/savon >= 0.9.8, < 2.17.2
Published Jul 31, 2026
Tracked Since Aug 01, 2026