Junglewise Threat Intelligence

CVE-2026-54904: ruby-concurrency concurrent-ruby denial of service in AtomicReference

CVE-2026-54904 · Severity: high · CVSS 3.1 · Published 2026-06-24

Technologies: concurrent-ruby (RubyGems). Vendors: RubyGems.

Executive brief

A vulnerability in the concurrent-ruby library, a tool used by Ruby developers to manage background tasks and data consistency, can cause applications to freeze. If the library processes a specific mathematical value (NaN), it enters an infinite loop that consumes 100% of the available processor power. This can lead to a complete service outage or "denial of service" where the application stops responding to users.

Technical details

A livelock vulnerability exists in Concurrent::AtomicReference#update due to the interaction between Ruby's NaN semantics and the library's retry logic. The #update method retries until compare_and_set returns true; however, compare_and_set performs a numeric equality check (==) before the atomic swap. Because Float::NAN == Float::NAN is always false in Ruby, the check fails indefinitely when the reference contains a NaN value. An attacker who can influence numeric data stored in an AtomicReference can trigger this infinite loop, leading to CPU exhaustion and thread hangs. The issue is resolved in version 1.3.7.

Affected products

  • ruby-concurrency concurrent-ruby < 1.3.7

Timeline

  • 2026-06-16: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: NVD publication date

References

Related threats