CVE-2026-34763: Ruby Unescaped Regex Stripping
An unescaped string is interpolated into a regular expression and used to strip content from a string using `.sub` or `.gsub`. If the variable contains regex metacharacters, the match may fail or behave unexpectedly. This can lead to information disclosure, such as exposing absolute internal paths. Use `Regexp.escape()` or `Regexp.quote()` to safely interpol
greprules fetch cve-2026-34763-ruby-unescaped-regex-stripping --engine opengrepDescription
An unescaped string is interpolated into a regular expression and used to strip content from a string using `.sub` or `.gsub`. If the variable contains regex metacharacters, the match may fail or behave unexpectedly. This can lead to information disclosure, such as exposing absolute internal paths. Use `Regexp.escape()` or `Regexp.quote()` to safely interpol
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.