{"id":"CVE-2018-3759","aliases":["GHSA-2xvj-j3qh-x8c3"],"url":"https://o3.security/vulnerability/CVE-2018-3759","summary":"private_address_check contains race condition","details":"private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.","published":"2018-06-13T15:29:00.267Z","modified":"2026-07-08T16:40:55.374785Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"private_address_check","fixedVersion":"0.5.0"}],"fix":{"url":"https://github.com/jtdowney/private_address_check/commit/4068228187db87fea7577f7020099399772bb147","label":"jtdowney/private_address_check@4068228"},"references":[{"type":"FIX","url":"https://github.com/jtdowney/private_address_check/commit/4068228187db87fea7577f7020099399772bb147"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:40:55.374785Z"}}