The current version of Ruby is 4.0.7 (as of 14/09/2026). patchletter checks the official source daily and emails you new releases.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Ruby: Mehrere Schwachstellen
WID-SEC-W-2026-3053 · 5 Oct
- Ruby: Mehrere Schwachstellen
WID-SEC-W-2026-2379 · 1 Oct
- Ruby und Ruby on Rails (erb gem): Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2026-1187 · 1 Oct
- Ruby: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2025-2215 · 1 Oct
- Ruby: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2025-2083 · 1 Oct
- Ruby: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2025-1472 · 1 Oct
- Ruby (CGI und URI gem): Mehrere Schwachstellen
WID-SEC-W-2025-0438 · 1 Oct
- Ruby: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2024-0952 · 1 Oct
Ruby at a glance
Ruby is a widely used programming language, notably behind Ruby on Rails and much tooling and automation. The Ruby core team ships a new minor version yearly, each maintained with bug and security fixes for a few years, plus security releases for the interpreter and standard library.
For admins Ruby is usually a runtime beneath an application (often Rails), whose requirements set the version. Apply security fixes promptly by moving the Ruby version in servers, containers and CI, and keep the end-of-life date of your minor version in view — running an unsupported Ruby is a common exposure. Version managers (rbenv, rvm) keep multiple Rubies in parallel; on updates, check the application and its native gems. The gem dependencies carry their own supply-chain risk — audit them (bundler-audit helps). Test the app before moving a major Ruby version. Patchletter surfaces new Ruby releases.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 4.0 | 4.0.7 | EOL 31 Mar 29 |
| 3.4 | 3.4.11 | EOL 31 Mar 28 |
| 3.3 | 3.3.12 | EOL 31 Mar 27 |
| 3.2 | 3.2.11 | End of Life |
| 3.1 | 3.1.7 | End of Life |
| 3.0 | 3.0.7 | End of Life |
| 2.7 | 2.7.8 | End of Life |
| 2.6 | 2.6.10 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 4.0.7 | STABLE | 14/09/2026 | Release notes → |
| 4.0.6 | STABLE | 13/07/2026 | Release notes → |
| 4.0.5 | STABLE | 19/05/2026 | Release notes → |
| 3.4.11 | STABLE | 23/09/2026 | – |
| 3.4.10 | STABLE | 30/06/2026 | – |
| 3.3.12 | STABLE | 16/07/2026 | – |
| 3.3.11 | STABLE | 26/03/2026 | – |
| 3.2.11 | STABLE | 27/03/2026 | – |
| 3.1.7 | STABLE | 26/03/2025 | – |
| 3.0.7 | STABLE | 23/04/2024 | – |
| 2.7.8 | STABLE | 30/03/2023 | – |
| 2.6.10 | STABLE | 12/04/2022 | – |
| 2.5.9 | STABLE | 05/04/2021 | – |
| 2.4.10 | STABLE | 31/03/2020 | – |
| 2.3.8 | STABLE | 17/10/2018 | – |
| 2.2.10 | STABLE | 28/03/2018 | – |
| 2.1.10 | STABLE | 31/03/2016 | – |
| 2.0.0p648 | STABLE | 16/12/2015 | – |
| 1.9.3p551 | STABLE | 13/11/2014 | – |
Frequently asked questions
- What is the latest version of Ruby?
- Ruby 4.0.7, released 14/09/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Ruby release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Ruby updates?
- Tick Ruby off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Ruby version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Ruby version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/ruby)https://patchletter.com/badge/ruby.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).