CVE-2026-67987 Details
Description
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two consecutive regular expressions and delay chat-completion processing
A denial-of-service vulnerability has been identified in the Ruby LLM library, specifically in the response parsing of think-tags. This issue is present in Ruby 3.1.x and arises from polynomial-time regular expression processing. When a model response includes numerous unterminated <think> tags, it can lead to excessive CPU usage by causing two consecutive regular expressions to run inefficiently. As a result, the processing of chat completions is delayed.
Users can upgrade to Ruby LLM version 2.0.0, which addresses this vulnerability by removing the think tag parsing from the content and adjusting the reasoning extraction to rely on the fields provided by the model, rather than the tags.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| crmne ruby_llm | ~3.1 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion