{"id":"GHSA-mx5j-mp4f-g8jg","summary":"Savon::Model evaluates WSDL operation names as Ruby source","details":"### Impact\n\n`Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the `.all_operations` class method provided by `Savon::Model` to automatically register all operations provided by the WSDL. Configuring `Savon::Model` with trusted operation names via `.operations` is safe.\n\n### Patches\n\nPatched in Savon 2.17.2.\n\nUsers should upgrade to 2.17.2 or later.\n\n### Workarounds\n\nAvoid `.all_operations` for untrusted WSDL documents. Use `.operations` with trusted operation names instead.","aliases":["CVE-2026-53510"],"modified":"2026-07-31T19:56:42.936890Z","published":"2026-07-31T19:38:25Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-31T19:38:25Z"},"references":[{"type":"WEB","url":"https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg"},{"type":"WEB","url":"https://github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/savon/CVE-2026-53510.yml"},{"type":"PACKAGE","url":"https://github.com/savonrb/savon"},{"type":"WEB","url":"https://github.com/savonrb/savon/releases/tag/v2.17.2"},{"type":"WEB","url":"https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-53510"}],"affected":[{"package":{"name":"savon","ecosystem":"RubyGems","purl":"pkg:gem/savon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.8"},{"fixed":"2.17.2"}]}],"versions":["0.9.10","0.9.11","0.9.14","0.9.8","0.9.9","1.0.0","1.1.0","1.2.0","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.10.0","2.10.1","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.13.0","2.13.1","2.14.0","2.15.0","2.15.1","2.16.0","2.17.0","2.17.1","2.2.0","2.3.0","2.3.1","2.3.2","2.3.3","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.8.0","2.8.1","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mx5j-mp4f-g8jg/GHSA-mx5j-mp4f-g8jg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}