excon
RubyGems2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting exconpage 1 of 1
- CVE-2019-16779MEDIUMCVSS 5.8EG 5.8✓ Fixed in 0.71.02019-12-16
vulnerable: 0.0.1 ... 0.9.6 (207 versions)
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returni…
- CVE-2026-54171MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.5.02026-07-10
vulnerable: 0.0.1 ... 1.4.2 (278 versions)
Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could ca…
Check whether excon is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for excon CVEs against the assets you own.
Start Free Scan →