Back

MEDIUM

YARD static cache reads raw traversal paths before router sanitization

Published Jun 19, 2026

Description

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue.

Affected products

Remediation

Red Hat statement

This Moderate impact path traversal vulnerability in YARD does not affect Red Hat products as the vulnerable code is not present.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 19, 2026
Updated Jun 22, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Jun 22, 2026
NVD
Status Deferred
Modified Jun 23, 2026
Red Hat
Severity Moderate
Public date Jun 19, 2026
ENISA EUVD
Assigner GitHub_M
Published Jun 19, 2026
Updated Jun 22, 2026
Exploited since n/a
EUVD-2026-38069 GHSA-PXCC-8665-PHX8