CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "length": 658.0, "function_hash": "185553476159107413192269642060714357735" }, "id": "CVE-2021-41819-2f76299c", "deprecated": false, "target": { "file": "ext/cgi/escape/escape.c", "function": "optimized_escape_html" }, "signature_type": "Function", "source": "https://github.com/ruby/ruby/commit/f69aeb83146be640995753667fdd6c6f157527f5" }, { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "221608888545214764521643589590002473795", "62837079863855754692353823286478885059", "151633818343694841750591657495653307518", "112628295566100827065348454738811594068" ] }, "id": "CVE-2021-41819-799f160e", "deprecated": false, "target": { "file": "ext/cgi/escape/escape.c" }, "signature_type": "Line", "source": "https://github.com/ruby/ruby/commit/f69aeb83146be640995753667fdd6c6f157527f5" } ] }