Synced 17 Jun 2026 22:27 UTC Account

Is Ruby 2.3.8 patched?

Ruby · cycle 2.3 · end of life · Official site ↗
2.3.829/100End of life

Current stable (4.0.5): 100/100

Minimum safe version2.7.7

2.3.8 has 7 open critical-or-high vulnerabilities. Run 2.7.7 or later to clear them. See what 2.7.7 fixes →

Health score29/100
Open issues10
Exploited now0
Cycle 2.3 EOL2019-03-31
Latest release4.0.5

Summary iPlain-English security status for Ruby 2.3.8, built from its CVEs, active-exploitation data, end-of-life date and latest release.

Ruby 2.3.8 is part of the 2.3 release line. 10 known vulnerabilities affect it. The minimum safe version is 2.7.7 — upgrade to it or later to clear the open critical/high issues. The 2.3 line reached end-of-life on 2019-03-31, so it no longer receives security patches. The latest supported Ruby release is 4.0.5.

Frequently asked

Is Ruby 2.3.8 patched?

Ruby 2.3.8 is end-of-life and no longer receives security patches. Move to 4.0.5.

What version should I upgrade Ruby 2.3.8 to?

Upgrade Ruby 2.3.8 to at least 2.7.7 to clear its 7 open critical-or-high vulnerabilities.

When does Ruby 2.3 reach end-of-life?

Ruby 2.3 reached end-of-life on 2019-03-31 and no longer receives security patches.

What is the latest version of Ruby?

The latest supported Ruby release is 4.0.5.

Is Ruby 2.3.8 still receiving security updates?

No — Ruby 2.3.8 is on the 2.3 line, which reached end-of-life on 2019-03-31 and no longer receives security updates. Upgrade to 4.0.5 or later to stay supported.

Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Ruby's official advisory before you patch or upgrade — Ruby official site ↗