rubygems
Security Advisories in rubygems
Moderate
17 days ago
guard-livereload has a directory traversal vulnerability
rubygems
guard-livereload
Critical
18 days ago
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
rubygems
activestorage
Low
18 days ago
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
rubygems
msgpack
High
18 days ago
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
rubygems
mcp
Moderate
18 days ago
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
rubygems
mcp
Moderate
19 days ago
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
rubygems
mcp
Moderate
19 days ago
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
rubygems
mcp
Low
19 days ago
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
rubygems
activerecord-tenanted
Moderate
20 days ago
Pagy I18n locale option is not validated before being used in a file path
rubygems
pagy
High
20 days ago
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
rubygems
oauth2
High
20 days ago
OAuth: Cross-origin token-request redirects can expose signed request metadata
rubygems
oauth
Low
20 days ago
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
rubygems
sqlite3, sqlite3-ruby
Low
20 days ago
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
rubygems
sqlite3, sqlite3-ruby
Moderate
24 days ago
Trix: Stored XSS via HTMLParser attribute injection on paste
rubygems, npm
action_text-trix, trix
Low
25 days ago
Ruby json: JSON generator heap buffer overflow when streaming to an IO
rubygems
json
Moderate
27 days ago
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
rubygems
rails-html-sanitizer
Low
27 days ago
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
rubygems
loofah
Moderate
27 days ago
Loofah: SVG `href` attribute bypasses local-reference restriction
rubygems
loofah
High
27 days ago
websocket-driver-ruby: Denial of service via malformed Host header
rubygems
websocket-driver
Low
27 days ago
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
rubygems
loofah
High
about 1 month ago
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
rubygems
datadog
Moderate
about 1 month ago
ViewComponent: Reused Component Instances Retain Stale Render Context
rubygems
view_component
Moderate
about 1 month ago
websocket-driver: Memory exhaustion in HTTP header parser
rubygems
websocket-driver
Moderate
about 1 month ago
websocket-driver: Resource limit bypass via message compression
rubygems
websocket-driver
Moderate
about 1 month ago
websocket-driver: Memory exhaustion via abuse of protocol length headers
rubygems
websocket-driver
Moderate
about 1 month ago
Decidim: Push subscriptions can be abused for server-side requests
rubygems
decidim-core
Moderate
about 1 month ago
Decidim: HTML content blocks allow stored script execution
rubygems
decidim-core
Moderate
about 1 month ago
Decidim: CSV census record endpoints improper authorization
rubygems
decidim-verifications
High
about 1 month ago
Decidim: JWT-backed authentication can be replayed across organizations
rubygems
decidim
High
about 1 month ago
Decidim: Verification documents can be downloaded through reusable links
rubygems
decidim-verifications
Moderate
about 1 month ago
Decidim: Private exports can be downloaded through reusable links
rubygems
decidim-core
Moderate
about 1 month ago
Decidim: Admin user search allows SQL injection through similarity-based sorting
rubygems
decidim-admin
Moderate
about 1 month ago
Decidim: Verification admins can access supplied IDs from other organizations
rubygems
decidim-verifications
Moderate
about 1 month ago
Decidim: Forms admin question editor lacks authorization
rubygems
decidim-demographics
Moderate
about 1 month ago
Excon does not redact additional sensitive/risky headers when following redirects
rubygems
excon
Moderate
about 1 month ago
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
rubygems
secure_headers
Moderate
about 1 month ago
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
rubygems
avo
High
about 1 month ago
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
rubygems
css_parser
High
about 2 months ago
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
rubygems
pay
Moderate
about 2 months ago
YARD static cache reads raw traversal paths before router sanitization
rubygems
yard
Moderate
about 2 months ago
fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
rubygems
fluent-plugin-opentelemetry
Low
about 2 months ago
fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`
rubygems
fluent-plugin-s3
High
about 2 months ago
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
rubygems
fluentd
High
about 2 months ago
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
rubygems
fluentd
High
about 2 months ago
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
rubygems
fluentd
Critical
about 2 months ago
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
rubygems
fluentd
Low
about 2 months ago
Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
rubygems
concurrent-ruby
Low
about 2 months ago
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
rubygems
concurrent-ruby
High
about 2 months ago
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
rubygems
concurrent-ruby
High
about 2 months ago
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
rubygems
oj
High
about 2 months ago
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
rubygems
oj
High
about 2 months ago
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
rubygems
oj
High
about 2 months ago
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
rubygems
oj
High
about 2 months ago
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
rubygems
oj
High
about 2 months ago
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
rubygems
faraday
High
about 2 months ago
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
rubygems
alchemy_cms
Low
about 2 months ago
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
rubygems
nokogiri
Low
about 2 months ago
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
rubygems
nokogiri
Low
about 2 months ago
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
rubygems
nokogiri
Moderate
about 2 months ago
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
rubygems
nokogiri
Low
about 2 months ago
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
rubygems
nokogiri
Low
about 2 months ago
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
rubygems
nokogiri
Low
about 2 months ago
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
rubygems
nokogiri
Critical
2 months ago
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
rubygems
avo
Moderate
2 months ago
katello: missing repository authorization in content_uploads exposes cross-product content existence
rubygems
katello
Low
2 months ago
Net::IMAP: Denial of Service via incomplete raw argument validation
rubygems
net-imap
Moderate
2 months ago
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
rubygems
net-imap
High
2 months ago
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
rubygems
puma
Moderate
2 months ago
Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret
rubygems
doorkeeper-openid_connect
Moderate
3 months ago
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
rubygems
carrierwave
High
3 months ago
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
rubygems
jwt
Low
3 months ago
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
rubygems
faraday
Moderate
3 months ago
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
rubygems
view_component
Moderate
3 months ago
view_component: Preview Route Can Dispatch Inherited Helper Methods
rubygems
view_component
Moderate
3 months ago
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
rubygems
devise
Moderate
3 months ago
Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL
rubygems
sidekiq-cron
High
3 months ago
katalyst-koi: Session cookies can be replayed after user logout
rubygems
katalyst-koi
Moderate
3 months ago
CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content
rubygems
css_parser
High
3 months ago
Nokogiri CSS selector tokenizer has regular expression backtracking
rubygems
nokogiri
Moderate
3 months ago
GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens
rubygems
graphql
Moderate
4 months ago
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
rubygems
net-imap
Moderate
4 months ago
net-imap vulnerable to command Injection via unvalidated Symbol inputs
rubygems
net-imap
Moderate
4 months ago
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
rubygems
net-imap
High
4 months ago
net-imap vulnerable to STARTTLS stripping via invalid response timing
rubygems
net-imap
Filter by Severity
Filter by Package
actionpack
59
nokogiri
56
rack
50
rubygems-update
25
activerecord
23
puppet
23
activesupport
17
rails-html-sanitizer
15
publify_core
15
camaleon_cms
15
puma
14
passenger
14
decidim
13
actionview
12
loofah
11
oj
11
activestorage
11
fat_free_crm
11
net-imap
10
rails
10
ruby-saml
10
openc3
9
decidim-core
9
rexml
8
avo
8
spree
8
katello
8
fluentd
7
org.jruby:jruby-stdlib
7
mcp
6
webrick
6
ember-source
6
devise
6
view_component
6
jquery-rails
6
json
6
doorkeeper
6
sinatra
6
grpc
5
bootstrap
5
commonmarker
5
sidekiq
5
yard
5
bootstrap
5
carrierwave
5
bundler
5
grpcio
5
cgi
5
websocket-driver
4
dragonfly
4
phlex
4
mail
4
bootstrap-sass
4
uri
4
decidim-admin
4
sanitize
4
action_text-trix
4
trix
4
rails_admin
4
devise-two-factor
3
bootstrap
3
jquery-ui
3
jQuery
3
git
3
rack-cors
3
org.webjars.npm:jquery-ui
3
omniauth-saml
3
sqlite3
3
openssl
3
decidim-verifications
3
faraday
3
json-jwt
3
com.google.protobuf:protobuf-java
3
com.google.protobuf:protobuf-kotlin
3
activeadmin
3
resque
3
httparty
3
rubyzip
3
gollum
3
google-protobuf
3
sqlite3-ruby
3
omniauth
3
jQuery.UI.Combined
3
concurrent-ruby
3
private_address_check
3
secure_headers
3
chartkick
3
rest-client
3
geminabox
3
spree_api
3
jquery-ui-rails
3
rdoc
3
io.grpc:grpc-protobuf
3
spina
3
jquery
2
sprockets
2
spree_auth_devise
2
oxidized-web
2
@openc3/tool-common
2
kramdown
2
oauth
2
omniauth-facebook
2
cocoapods-downloader
2
VladTheEnterprising
2
openc3-cosmos-tool-iframe
2
pay
2
excon
2
faye
2
facter
2
pdfkit
2
yajl-ruby
2
alchemy_cms
2
com.google.protobuf:protobuf-javalite
2
solidus_core
2
logstash-core
2
redcarpet
2
bootstrap-sass
2
pageflow
2
sidekiq-unique-jobs
2
css_parser
2
echor
2
twbs/bootstrap
2
doorkeeper-openid_connect
2
administrate
2
google_sign_in
2
activejob
2
graphql
2
addressable
2
ox
2
iodine
2
radiant
2
paperclip
2
lodash-es
2
actiontext
2
org.webjars:bootstrap
2
lodash-rails
2
bson
2
rack-session
2
mini_magick
2
red-arrow
2
solidus_frontend
2
lodash
2
sup
2
git-fastclone
2
net-ldap
2
safemode
2
com.google.protobuf:protobuf-kotlin-lite
2
pwpush
2
qiita-markdown
2
decidim-templates
2
field_test
2
decidim-meetings
2
ruby-openid
2
mechanize
2
org.webjars.npm:jquery
2
actionmailer
2
kaminari
2
i18n
2
pghero
2
bsv-sdk
2
net.sf.mpxj-for-csharp
1
kelredd-pruview
1
gemirro
1
pgsync
1
authlogic
1
sequenceserver
1
github.com/pubnub/go/v7
1
awesome-bot
1
msgpack
1
pagy
1
clearance
1
web-console
1
rbovirt
1
vagrant
1
faye-websocket
1
better_errors
1
solidus_backend
1
open-uri-cached
1
github.com/Shopify/ejson2env/v2
1
curl
1
karteek-docsplit
1
openshift-origin-controller
1
geokit-rails
1
com.pubnub:pubnub
1
gibbon
1
mixlib-archive
1
datagrid
1
Pubnub
1
thumbshooter
1
sigstore
1
spree_storefront
1
pubnub
1
thin
1
smalruby
1
logstash
1
Autolab
1
exiftool_vendored
1
sha3
1
resolv
1
lodash.trim
1
Filter by Repository
https://github.com/rails/rails
70
https://github.com/sparklemotion/nokogiri
35
https://github.com/rack/rack
29
https://github.com/rubygems/rubygems
18
https://github.com/puppetlabs/puppet
15
https://github.com/decidim/decidim
15
https://github.com/rails/rails-html-sanitizer
14
https://github.com/publify/publify
14
https://github.com/puma/puma
12
https://github.com/phusion/passenger
11
https://github.com/owen2345/camaleon-cms
11
https://github.com/fatfreecrm/fat_free_crm
9
https://github.com/ruby/rexml
8
https://github.com/SAML-Toolkits/ruby-saml
7
https://github.com/flavorjones/loofah
6
https://github.com/doorkeeper-gem/doorkeeper
6
https://github.com/jquery/jquery
6
https://github.com/sinatra/sinatra
6
https://github.com/solidusio/solidus
5
https://github.com/OpenC3/cosmos
5
https://github.com/twbs/bootstrap
5
https://github.com/Katello/katello
4
https://github.com/mikel/mail
4
https://github.com/ruby/webrick
4
https://github.com/grpc/grpc
4
https://github.com/avo-hq/avo
4
https://github.com/ruby/openssl
4
https://github.com/carrierwaveuploader/carrierwave
4
https://github.com/markevans/dragonfly
4
https://github.com/rgrove/sanitize
4
https://github.com/jtdowney/private_address_check
3
https://github.com/ruby-git/ruby-git
3
https://github.com/phlex-ruby/phlex
3
https://github.com/fluent/fluentd
3
https://github.com/spree/spree
3
https://github.com/cyu/rack-cors
3
https://github.com/gollum/gollum
3
https://github.com/gjtorikian/commonmarker
3
https://github.com/rest-client/rest-client
3
https://github.com/ruby/uri
3
https://github.com/ruby/cgi
3
https://github.com/geminabox/geminabox
3
https://github.com/rubyzip/rubyzip
3
https://github.com/sidekiq/sidekiq
3
https://github.com/protocolbuffers/protobuf
3
https://github.com/rubygems/rubygems.org
3
https://github.com/resque/resque
3
https://github.com/lsegal/yard
3
https://github.com/activeadmin/activeadmin
3
https://github.com/lodash/lodash
2
https://github.com/sparklemotion/mechanize
2
https://github.com/CocoaPods/cocoapods-downloader
2
https://github.com/faye/faye
2
https://github.com/ruby-ldap/ruby-net-ldap
2
https://github.com/vmg/redcarpet
2
https://github.com/brianmario/yajl-ruby
2
https://github.com/ruby/rdoc
2
https://github.com/ankane/field_test
2
https://github.com/jnunemaker/httparty
2
https://github.com/basecamp/google_sign_in
2
https://github.com/openid/ruby-openid
2
https://github.com/solidusio/solidus_auth_devise
2
https://github.com/codevise/pageflow
2
https://github.com/increments/qiita-markdown
2
https://github.com/gettalong/kramdown
2
https://github.com/svenfuchs/safemode
2
https://github.com/twitter/secure_headers
2
https://github.com/ohler55/ox
2
https://gitlab.com/gitlab-org/cves
2
https://github.com/emberjs/ember.js
2
https://github.com/square/git-fastclone
2
https://github.com/railsadminteam/rails_admin
2
https://github.com/thoughtbot/paperclip
2
https://github.com/ankane/pghero
2
https://github.com/mperham/sidekiq
2
https://github.com/mhenrixon/sidekiq-unique-jobs
2
https://github.com/ruby/net-imap
2
https://github.com/kaminari/kaminari
2
https://github.com/ytti/oxidized-web
2
https://github.com/github/cmark-gfm
2
https://github.com/tinfoil/devise-two-factor
2
https://github.com/omniauth/omniauth
2
https://github.com/sup-heliotrope/sup
2
https://github.com/plataformatec/devise
2
https://github.com/ankane/chartkick
2
https://github.com/rack/rack-session
2
https://github.com/jquery/jquery-ui
2
https://github.com/svenfuchs/i18n
2
https://github.com/pglombardo/PasswordPusher
2
https://github.com/nov/json-jwt
2
https://github.com/mongodb/bson-ruby
2
https://github.com/jnunemaker/crack
1
https://github.com/rcook/rgpg
1
https://github.com/cgriego/active_attr
1
https://github.com/theforeman/foreman_fog_proxmox
1
https://github.com/ManageIQ/awesome_spawn
1
https://github.com/theforeman/foreman_ansible
1
https://github.com/bdmac/strong_password
1
https://github.com/affix/CVE-2022-36231
1
https://github.com/rsantamaria/papercrop
1
https://github.com/Shopify/ejson2env
1
https://github.com/rack/rack-contrib
1
https://github.com/rails/globalid
1
https://github.com/ruby/resolv
1
https://github.com/spree/spree_auth_devise
1
https://github.com/zvory/csv-safe
1
https://github.com/ankane/pgsync
1
https://github.com/wconrad/ftpd
1
https://github.com/camilova/activerecord-update-by-case
1
https://github.com/hopsoft/turbo_boost-commands
1
https://github.com/sferik/rails_admin
1
https://github.com/pay-rails/pay
1
https://github.com/zenspider/ruby_parser-legacy
1
https://github.com/getsentry/raven-ruby
1
https://github.com/alexreisner/geocoder
1
https://github.com/postrank-labs/goliath
1
https://github.com/mislav/will_paginate
1
https://github.com/rails/sprockets
1
https://github.com/sporkmonger/addressable
1
https://github.com/ruby/fileutils
1
https://github.com/opscode/chef
1
https://github.com/ruby/date
1
https://github.com/tzinfo/tzinfo
1
https://github.com/octokit/octopoller.rb
1
https://github.com/padrino/padrino-contrib
1
https://github.com/twbs/bootstrap-sass
1
https://github.com/rails/web-console
1
https://github.com/sinatra/rack-protection
1
https://github.com/bbatsov/rubocop
1
https://github.com/beenhero/omniauth-weibo-oauth2
1
https://github.com/opensearch-project/opensearch-ruby
1
https://github.com/mongoid/moped
1
https://github.com/alphagov/tech-docs-gem
1
https://github.com/mkdynamic/omniauth-facebook
1
https://gitlab.com/2013/11
1
https://github.com/janko/image_processing
1
https://github.com/aws/aws-sdk-ruby
1
https://github.com/jwt/ruby-jwe
1
https://github.com/josh/rack-ssl
1
https://github.com/sparklemotion/sqlite3-ruby
1
https://github.com/octokit/octokit.rb
1
https://github.com/Shopify/pitchfork
1
https://github.com/njh/ruby-mqtt
1
https://github.com/basecamp/easymon
1
https://github.com/railsdog/spree
1
https://github.com/Snorby/snorby
1
https://github.com/inukshuk/bibtex-ruby
1
https://github.com/macournoyer/thin
1
https://github.com/ua-parser/uap-ruby
1
https://github.com/voloko/twitter-stream
1
https://github.com/resque/resque-scheduler
1
https://github.com/halostatue/minitar
1
https://github.com/shardlab/discordrb
1
https://github.com/fluent/fluentd-ui
1
https://github.com/rmosolgo/graphql-ruby
1
https://github.com/pubnub/javascript
1
https://github.com/omniauth/omniauth-rails
1
https://github.com/synth/omniauth-microsoft_graph
1
https://github.com/rails/activeresource
1
https://github.com/spejman/festivaltts4r
1
https://github.com/ahorner/text-helpers
1
https://github.com/tigris/open-uri-cached
1
https://github.com/restforce/restforce
1
https://github.com/ruby-grape/grape
1
https://github.com/thoughtbot/clearance
1
https://github.com/rubygems/bundler
1
https://github.com/jmespath/jmespath.rb
1
https://github.com/sisimai/rb-sisimai
1
https://github.com/onelogin/ruby-saml
1
https://github.com/ejschmitt/delayed_job_web
1
https://github.com/jordansissel/ruby-arr-pm
1
https://github.com/steveklabnik/request_store
1
https://github.com/nhosoya/omniauth-apple
1
https://github.com/flori/json
1
https://github.com/Shopify/job-iteration
1
https://github.com/unpoly/unpoly-rails
1
https://github.com/ankane/clockwork_web
1
https://github.com/omniauth/omniauth-saml
1
https://github.com/stimulusreflex/stimulus_reflex
1
https://github.com/rahult/karo
1
https://github.com/bundler/bundler
1
https://github.com/matestack/matestack-ui-core
1
https://github.com/wurmlab/sequenceserver
1
https://github.com/chef/mixlib-archive
1
https://github.com/ankane/chartkick.js
1
https://github.com/Gurpartap/aescrypt
1
https://github.com/jekyll/jekyll
1
https://github.com/airbrake/airbrake-ruby
1
https://github.com/rmagick/rmagick
1
https://github.com/ruby/ruby
1
https://github.com/Shopify/measured
1
https://github.com/github/view_component
1
https://github.com/boazsegev/iodine
1
https://github.com/auth0/omniauth-auth0
1
https://github.com/schneems/wicked
1
https://github.com/rails/actionpack-page_caching
1
https://github.com/petergoldstein/dalli
1
https://github.com/paragbagul111/CVE-2023-30145
1
https://github.com/adamzaninovich/sounder
1