CVE-2026-67989
Received Received - Intake

Regular Expression DoS in Ruby 3.1.x with Mistral Model Matching

Vulnerability report for CVE-2026-67989, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
crmne ruby_llm From 3.1.0 (inc) to 3.2.0 (exc)
crmne ruby_llm From 3.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a regular expression denial-of-service (ReDoS) issue in the ruby_llm gem's Mistral provider. It occurs when processing long model IDs containing repeated 'voxtral' strings without matching suffixes. The original regex patterns like /voxtral.*tts/ and /voxtral.*transcribe/ caused quadratic time complexity, making the system slow or unresponsive when handling such inputs.

Detection Guidance

This vulnerability is specific to the ruby_llm gem's Mistral provider and involves inefficient regex pattern matching in Ruby 3.1.x. To detect it, check if your application uses the ruby_llm gem version affected by CVE-2026-67989 and inspect model ID handling for Voxtral variants. Look for regex patterns like /voxtral.*tts/ or /voxtral.*transcribe/ in your codebase.

Impact Analysis

If you use the ruby_llm gem with Ruby 3.1.x and interact with Mistral AI models, an attacker could send a specially crafted model ID to trigger the ReDoS. This could cause your application to slow down significantly or become unresponsive, potentially leading to denial-of-service conditions in your system.

Mitigation Strategies

Update the ruby_llm gem to the latest version that includes the fix for CVE-2026-67989. Replace regex-based model ID checks with the new String#index-based methods (voxtral_followed_by? and voxtral_modalities_for) as shown in the patched capabilities.rb file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67989. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart