savon vulnerability

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.

Published 31 Jul 2026Updated 9 Sep 20263 sources
CVSS 8.1

Source timeline

CVE record published by NVDView source ↗