{"cves":["CVE-2026-33210","CVE-2026-41316"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"ruby\n[4.0.3-32]\n- Upgrade to Ruby 4.0.3.\n  Resolves: RHEL-171933\n- Fix ERB: Arbitrary code execution via deserialization bypass\n (CVE-2026-41316)\n  Resolves: RHEL-171258\n- Fix JSON: Denial of Service or Information Disclosure via format string injection\n (CVE-2026-33210)\n Resolves: RHEL-173458\n\nrubygem-mysql2\n[0.5.7-1]\n- Upgrade to mysql2 0.5.7.\n  Related: RHEL-142278\n\nrubygem-pg\n[1.6.3-1]\n- Upgrade to pg 1.6.3\n  Related: RHEL-142278","id":"ELSA-2026-20596","ovalId":"oval:com.oracle.elsa:def:202620596","source":"oracle_linux","title":"ELSA-2026-20596:  ruby:4.0 security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-20596.html"}