CVE-2026-46727: Use-after-free in pthread-based getaddrinfo timeout handler
A use-after-free vulnerability has been discovered in the pthread-based getaddrinfo timeout handler of Ruby. This vulnerability has been assigned the CVE identifier CVE-2026-46727. This issue has been fixed in Ruby 4.0.5. We recommend upgrading Ruby. Details A race condition exists in the timeout…
Sources
- T1CVE-2026-46727: Use-after-free in pthread-based getaddrinfo timeout handlerLanguage blogs: Rust / Go / TypeScript / Swift / Kotlin / Java / .NET / Ruby / PHP / Elixir / ISO C++