active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
CVE-2013-0156
This CVE was only ever scored under CVSS v2.0. NVD CVSS v2.0 base 7.5 — v2 rates that HIGH (v2 bands: LOW 0.0–3.9 / MEDIUM 4.0–6.9 / HIGH 7.0–10.0; v2 has no CRITICAL band). Vector AV:N/AC:L/Au:N/C:P/I:P/A:P. CVSS v2 is an older, coarser metric than v3.1/v4.0 (no Scope, no User Interaction, no Attack Requirements), so it is not directly comparable to a v3 or v4 score. NVD has never re-scored this record under v3. EPSS predicts 99.4% exploitation probability in the next 30 days, which is reflected in EG Risk but does not lift the v2 base. Confidence: LOW.
- High exploitation likelihood — EPSS 99%
- Public exploit code is available (Metasploit, Exploit-DB (verified), epss top5pct, epss high, public exploit)
A fix is available — apply it.
- CVSS v2.0 (legacy)
- 7.5HIGHNVD never assigned a CVSS v3 rating to this CVE
- EG Score
- 7.5(low)
- EG Risk
- 78(Track)EG Risk 78/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation99% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 99%
- EPSS %ILE
- 100%
- KEV
- Not listed
Published
January 13, 2013
Last Modified
April 29, 2026
References (28)
- secalert@redhathttp://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A
- secalert@redhathttp://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html
- secalert@redhathttp://rhn.redhat.com/errata/RHSA-2013-0153.html
- secalert@redhathttp://rhn.redhat.com/errata/RHSA-2013-0154.html
- secalert@redhathttp://rhn.redhat.com/errata/RHSA-2013-0155.html
- secalert@redhathttp://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/
- secalert@redhathttp://www.debian.org/security/2013/dsa-2604
- secalert@redhathttp://www.fujitsu.com/global/support/software/security/products-f/sw-sv-rcve-ror201301e.html
- secalert@redhathttp://www.insinuator.net/2013/01/rails-yaml/
- secalert@redhathttp://www.kb.cert.org/vuls/id/380039
- secalert@redhathttp://www.kb.cert.org/vuls/id/628463
- secalert@redhathttps://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156
- secalert@redhathttps://groups.google.com/group/rubyonrails-security/msg/c1432d0f8c70e89d?dmode=source&output=gplain
- secalert@redhathttps://puppet.com/security/cve/cve-2013-0156
- af854a3a-2127-422b-91ae-364da2661108http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A
Vendor Advisories for CVE-2013-0156(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | rubygem-activesupport-1:3.0.10-5.el6cf | 2013-01-10 | redhat |
| redhat | rubygem-activesupport-1:3.0.13-2.el6op | 2013-01-10 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
RubyGems(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| actionpack | 3.2.0 ... 3.2.9.rc3 (21 versions) | 3.2.11 | — |
Additional Vendor Advisories
(2)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 7× in last 7d / 10× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-26 13:47 UTCEG score recompute▲ 7.50
- 2026-07-23 01:13 UTCVendor advisory
- 2026-07-23 01:11 UTCVendor advisory
- 2026-07-23 01:09 UTCEG score recompute▼ 9.00
- 2026-07-23 00:12 UTCEG score recompute
- 2026-07-22 21:50 UTCEG score recompute
- 2026-07-22 14:50 UTCOSV refresh
- 2026-07-11 08:23 UTCEPSS rescore
- 2026-07-05 10:29 UTCOSV refresh
- 2026-07-01 15:02 UTCEPSS rescore
- 2026-06-16 21:35 UTCOSV refresh
- 2026-06-15 17:44 UTCEPSS rescore
- 2026-06-12 23:08 UTCEPSS rescore
- 2026-06-10 13:18 UTCEPSS rescore
- 2026-06-08 14:14 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-05 22:44 UTCEPSS rescore
- 2026-06-05 22:44 UTCEPSS rescore
- 2026-05-29 13:41 UTCEPSS rescore
- 2026-05-29 13:41 UTCEPSS rescore
- 2026-05-29 01:21 UTCEG score recompute
- 2026-05-29 01:21 UTCVendor advisory
- 2026-05-28 13:42 UTCEPSS rescore
- 2026-05-28 13:42 UTCEPSS rescore
Show 4 moreShow fewer
- 2026-05-28 13:42 UTCEPSS rescore
- 2026-05-20 20:03 UTCOSV refresh
- 2026-05-18 21:29 UTCEPSS rescore
- 2026-05-18 21:29 UTCEPSS rescore
Publicly available exploits
(6 references)Working exploit code is in the public domain (3 Metasploit modules) (1 GitHub PoC) (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-27527✓ verifiedFirst seen Aug 12, 2013
Ruby on Rails - Known Secret Session Cookie Remote Code Execution (Metasploit)
Open source ↗ - Metasploitexploit/multi/http/rails_secret_deserialization✓ verifiedFirst seen Apr 11, 2013
Ruby on Rails Known Secret Session Cookie Remote Code Execution
Open source ↗ - GitHub PoCbsodmike/rails-exploit-cve-2013-0156First seen Jan 12, 2013
Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156
Open source ↗ - Exploit-DBEDB-24019✓ verifiedFirst seen Jan 10, 2013
Ruby on Rails - XML Processor YAML Deserialization Code Execution (Metasploit)
Open source ↗ - Metasploitexploit/multi/http/rails_xml_yaml_code_exec✓ verifiedFirst seen Jan 7, 2013
Ruby on Rails XML Processor YAML Deserialization Code Execution
Open source ↗ - Metasploitauxiliary/scanner/http/rails_xml_yaml_scanner✓ verifiedFirst seen Jan 1, 2013
Ruby on Rails XML Processor YAML Deserialization Scanner
Open source ↗
Frequently asked(4)
What is CVE-2013-0156?
When was CVE-2013-0156 disclosed?
Is CVE-2013-0156 actively exploited?
How do I remediate CVE-2013-0156?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-0156
Is Your Infrastructure Affected by CVE-2013-0156?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.