RubyGems incidents
Recent RubyGems vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
kobako: 0.1.0 → 0.9.1
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
json: 2.20.0 → 2.21.2
guard-livereload has a directory traversal vulnerability
guard-livereload has a directory traversal vulnerability
guard-livereload: before 2.5.2
Savon::Model evaluates WSDL operation names as Ruby source
Savon::Model evaluates WSDL operation names as Ruby source
savon: 0.9.8 → 2.17.2
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
mcp: before 0.23.0
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
mcp: before 0.23.0
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
mcp: before 0.23.0
MCP Ruby SDK: Ruby SSE Session Poisoning
MCP Ruby SDK: Ruby SSE Session Poisoning
mcp: before 0.23.0
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
mcp: before 0.23.0
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
msgpack: before 1.8.2
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
activestorage: before 7.2.3.2
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
activerecord-tenanted: before 0.7.0
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
oauth2: 0.4.0 → 2.0.22
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
loofah: 2.25.0 → 2.25.2
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
rails-html-sanitizer: 1.0.3 → 1.7.1
Loofah: SVG `href` attribute bypasses local-reference restriction
Loofah: SVG `href` attribute bypasses local-reference restriction
loofah: before 2.25.2
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
loofah: 2.25.0 → 2.25.2
websocket-driver: Memory exhaustion in HTTP header parser
websocket-driver: Memory exhaustion in HTTP header parser
websocket-driver: before 0.8.1
websocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
websocket-driver: before 0.8.1
websocket-driver: Memory exhaustion via abuse of protocol length headers
websocket-driver: Memory exhaustion via abuse of protocol length headers
websocket-driver: before 0.8.1
Excon does not redact additional sensitive/risky headers when following redirects
Excon does not redact additional sensitive/risky headers when following redirects
excon: before 1.5.0
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
concurrent-ruby: before 1.3.7
katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: before 4.21.0.rc1
Trix has a Stored XSS vulnerability through serialized attributes
Trix has a Stored XSS vulnerability through serialized attributes
action_text-trix: before 2.1.17
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
omniauth-saml: 2.0.0 → 2.1.2
SAML authentication bypass via Incorrect XPath selector
SAML authentication bypass via Incorrect XPath selector
ruby-saml: before 1.12.3
fugit parse and parse_nat stall on lengthy input
fugit parse and parse_nat stall on lengthy input
fugit: before 1.11.1
Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
nokogiri: before 1.16.5
Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062
Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062
nokogiri: 1.16.0 → 1.16.2
HTTP response splitting in CGI
HTTP response splitting in CGI
cgi: 0.3.0 → 0.3.5
Buffer overrun in CGI.escape_html
Buffer overrun in CGI.escape_html
cgi: 0.3.0 → 0.3.1
Tooling for RubyGems
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.