YARD static cache reads raw traversal paths before router sanitization
Published Jun 19, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.40%
Description
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue.
Affected products
-
- Version < 0.9.44StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat 3scale API Management Platform 2
3scale-amp2/backend-rhel8
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel7
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel8
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel9
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp21/backend
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp21/system
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp22/backend
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp22/system
Not affected
Red Hat Hardened Images
nghttp2
Not affected
Red Hat Hardened Images
rust
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/backend-rhel8 | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel7 | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel8 | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel9 | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/backend | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/system | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/backend | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/system | Not affected | n/a |
| Red Hat Hardened Images | nghttp2 | Not affected | n/a |
| Red Hat Hardened Images | rust | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact path traversal vulnerability in YARD does not affect Red Hat products as the vulnerable code is not present.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-49342 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2490894 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38069 Advisory
- https://github.com/advisories/GHSA-pxcc-8665-phx8 Advisory
- https://github.com/lsegal/yard/commit/f78c19f0dd33a407085b4ed181bb60c0aa0078b4 x_refsource_MISC
- https://github.com/lsegal/yard/security/advisories/GHSA-pxcc-8665-phx8 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-49342
- https://www.cve.org/CVERecord?id=CVE-2026-49342
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-49342 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2490894 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38069 | Advisory | |
| https://github.com/advisories/GHSA-pxcc-8665-phx8 | Advisory | |
| https://github.com/lsegal/yard/commit/f78c19f0dd33a407085b4ed181bb60c0aa0078b4 | x_refsource_MISC | |
| https://github.com/lsegal/yard/security/advisories/GHSA-pxcc-8665-phx8 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-49342 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-49342 |
Change history (0)
No recorded changes yet.