ManageIQ / ManageIQ/optimist

CVE-2026-54906 (Medium) detected in concurrent-ruby-1.3.6.gem

Open Beginner friendly
#222 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
Ruby
Stars
259
Forks
35
PR merge metrics
No merged PRs in 30d

Description

## CVE-2026-54906 - Medium Severity Vulnerability
Vulnerable Library - concurrent-ruby-1.3.6.gem

Modern concurrency tools including agents, futures, promises, thread pools, actors, supervisors, and more.
Inspired by Erlang, Clojure, Go, JavaScript, actors, and classic concurrency patterns.


Library home page: https://rubygems.org/gems/concurrent-ruby-1.3.6.gem


Path to dependency file: /Gemfile.lock


Path to vulnerable library: /vendor/cache/concurrent-ruby-1.3.6.gem


Dependency Hierarchy:
- manageiq-style-1.6.0.gem (Root Library)
- more_core_extensions-4.5.1.gem
- activesupport-8.1.2.gem
- :x: **concurrent-ruby-1.3.6.gem** (Vulnerable Library)

Found in base branch: master



Vulnerability Details



concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent::ResourceLimitError. This is a synchronization correctness issue in the public Concurrent::ReadWriteLock API. This vulnerability is fixed in 1.3.7.

Publish Date: 2026-06-24

URL: CVE-2026-54906



CVSS 3 Score Details (4.0)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Release Date: 2026-06-19


Fix Resolution: https://github.com/ruby-concurrency/concurrent-ruby.git - v1.3.7

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

Open the contributing guide

Research direction

Start with /Gemfile.lock and the dependency hierarchy shown in the issue to trace concurrent-ruby through more_core_extensions and activesupport. Update the vulnerable dependency and the cached gem under /vendor/cache, then confirm the resolved version is 1.3.7 rather than 1.3.6.

Written by the indexing model from the issue text.

Assessment

Tech stack
ruby
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.