Security Advisory

CVE-2026-53510

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-31 19:38:33
Last updated 2026-07-31 20:04:21
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.