
blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits
Preview meta tags from the blog.trailofbits.com website.
Linked Hostnames
25- 15 links togithub.com
- 12 links toblog.trailofbits.com
- 3 links tonvd.nist.gov
- 2 links todevcraft.io
- 2 links tonastystereo.com
- 2 links tophrack.org
- 2 links toruby-doc.org
- 2 links tostaaldraad.github.io
Thumbnail
Search Engine Appearance
Marshal madness: A brief history of Ruby deserialization exploits
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
Bing
Marshal madness: A brief history of Ruby deserialization exploits
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
DuckDuckGo

Marshal madness: A brief history of Ruby deserialization exploits
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
General Meta Tags
7- titleMarshal madness: A brief history of Ruby deserialization exploits -The Trail of Bits Blog
- charsetUTF-8
- viewportwidth=device-width,initial-scale=1
- descriptionThis post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
- article:sectionposts
Open Graph Meta Tags
7- og:urlhttps://blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits/
- og:site_nameThe Trail of Bits Blog
- og:titleMarshal madness: A brief history of Ruby deserialization exploits
- og:descriptionThis post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
og:locale
en_us
Twitter Meta Tags
4- twitter:cardsummary_large_image
- twitter:imagehttps://blog.trailofbits.com/img/ruby-deserialization-exploits-timeline.svg
- twitter:titleMarshal madness: A brief history of Ruby deserialization exploits
- twitter:descriptionThis post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
Item Prop Meta Tags
7- nameMarshal madness: A brief history of Ruby deserialization exploits
- descriptionThis post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
- datePublished2025-08-19T07:00:00-04:00
- dateModified2025-08-20T00:00:00-04:00
- wordCount2041
Link Tags
11- dns-prefetch//fonts.googleapis.com
- dns-prefetch//fonts.gstatic.com
- preconnecthttps://fonts.gstatic.com
- preload stylesheet/css/syntax.css
- shortcut icon/favicon.png
Links
57- https://blog.includesecurity.com/2024/03/discovering-deserialization-gadget-chains-in-rubyland
- https://blog.trailofbits.com
- https://blog.trailofbits.com/2024/03/29/introducing-ruzzy-a-coverage-guided-ruby-fuzzer
- https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-2
- https://blog.trailofbits.com/2024/12/11/auditing-the-ruby-ecosystems-central-package-repository