USN-8394-1: YARD vulnerability

Publication date

5 June 2026

Overview

YARD could be made to expose sensitive information over the network.


Packages

  • yard - A documentation generation tool for the Ruby programming language

Details

It was discovered that YARD incorrectly sanitized paths in its built-in
documentation server. An attacker could possibly use this issue to read arbitrary
files from the server host.

It was discovered that YARD incorrectly sanitized paths in its built-in
documentation server. An attacker could possibly use this issue to read arbitrary
files from the server host.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute yard –  0.9.38-1ubuntu0.1~esm1  
yard-doc –  0.9.38-1ubuntu0.1~esm1  
24.04 LTS noble yard –  0.9.36-1ubuntu0.1~esm1  
yard-doc –  0.9.36-1ubuntu0.1~esm1  
22.04 LTS jammy yard –  0.9.26-1ubuntu0.1+esm1  
yard-doc –  0.9.26-1ubuntu0.1+esm1  
20.04 LTS focal yard –  0.9.24-1+deb11u1ubuntu0.1~esm1  
yard-doc –  0.9.24-1+deb11u1ubuntu0.1~esm1  
18.04 LTS bionic yard –  0.9.12-2ubuntu0.1~esm2  
yard-doc –  0.9.12-2ubuntu0.1~esm2  
16.04 LTS xenial yard –  0.8.7.6+git20160220-3ubuntu0.1~esm2
yard-doc –  0.8.7.6+git20160220-3ubuntu0.1~esm2

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›