{"id":"CVE-2014-10077","aliases":["GHSA-34hf-g744-jw64"],"url":"https://o3.security/vulnerability/CVE-2014-10077","summary":"i18n Vulnerable to Denial of Service Attack","details":"Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.","published":"2018-11-06T15:29:00Z","modified":"2026-04-16T06:25:06.143450459Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.03079,"percentile":0.86633,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"i18n","fixedVersion":"0.8.0"}],"fix":{"url":"https://github.com/rubysec/ruby-advisory-db/pull/182/files","label":"rubysec/ruby-advisory-db#182"},"references":[{"type":"ADVISORY","url":"https://github.com/rubysec/ruby-advisory-db/pull/182/files"},{"type":"ADVISORY","url":"https://github.com/svenfuchs/i18n/pull/289"},{"type":"ADVISORY","url":"https://github.com/svenfuchs/i18n/releases/tag/v0.8.0"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00021.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-10077"},{"type":"WEB","url":"https://github.com/ruby-i18n/i18n/pull/250/commits/08293a41b34e93824563ca0f5b9b97e7451b6387"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/i18n/CVE-2014-10077.yml"},{"type":"PACKAGE","url":"https://github.com/svenfuchs/i18n"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T06:25:06.143450459Z"}}