# Ruby CVE-2026-41316: ERB @_init deserialization guard bypass via def_module / def_method / def_class - Product: Ruby (https://whatsnew.fyi/product/ruby) - Vendor: Ruby - Date: 2026-04-21 - Original notes: https://www.ruby-lang.org/en/news/2026/04/21/erb-cve-2026-41316/ - Permalink: https://whatsnew.fyi/product/ruby/releases/2026-04-21-cve-2026-41316-erb-init-deserialization-guard-byp What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- We published security advisory for CVE-2026-41316. CVE-2026-41316: ERB @_init deserialization guard bypass via def_module / def_method / def_class A deserialization vulnerability exists in ERB. This v… - **security** — Fix deserialization vulnerability in ERB @_init guard bypass via def_module, def_method, and def_class