Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-67986

CVE-2026-67986: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.8

    High [CVE-2026-67986] Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep

    CVE-2026-67986Source published Source updated

    amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names. A flaw was found in amazing_print. This vulnerability allows an attacker to inject and execute arbitrary Ruby code within the host process. Red Hat Satellite includes the rubygem-amazing_print package as a dependency of the hammer CLI tool. While the vulnerable code exists in the shipped version, the specific code path that enables…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • No action is required. The vulnerable code path in amazing_print is not reachable through normal Satellite operation. Customers who have developed custom scripts or plugins that call amazing_print's method array grep with a block should avoid passing untrusted input into method introspection until an upstream fix is available.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery