{"id":"CVE-2014-10077","aliases":["GHSA-34hf-g744-jw64"],"url":"https://o3.security/vulnerability/CVE-2014-10077","summary":"i18n Vulnerable to Denial of Service Attack","details":"Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.","published":"2018-11-06T15:29:00Z","modified":"2026-04-16T06:25:06.143450459Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"i18n","fixedVersion":"0.8.0"}],"fix":{"url":"https://github.com/rubysec/ruby-advisory-db/pull/182/files","label":"rubysec/ruby-advisory-db#182"},"references":[{"type":"ADVISORY","url":"https://github.com/rubysec/ruby-advisory-db/pull/182/files"},{"type":"ADVISORY","url":"https://github.com/svenfuchs/i18n/pull/289"},{"type":"ADVISORY","url":"https://github.com/svenfuchs/i18n/releases/tag/v0.8.0"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00021.html"},{"type":"FIX","url":"https://github.com/rubysec/ruby-advisory-db/pull/182/files"},{"type":"FIX","url":"https://github.com/svenfuchs/i18n/pull/289"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T06:25:06.143450459Z"}}