CVE-2026-54463: Ruby Varint Unbounded Accumulationcve-2026-54463-ruby-varint-unbounded-accumulation
Variable-length integers are accumulated from an input stream without validation. An attacker can send an endless stream of crafted bytes to cause a Denial of Service (DoS) via memory exhaustion as the integer grows iteratively. Ensure that the accumulated length is checked against a maximum limit immediately during parsing.