RubyGems incidents

Recent RubyGems vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

MODERATERubyGems

guard-livereload has a directory traversal vulnerability

guard-livereload has a directory traversal vulnerability

guard-livereload: before 2.5.2

5 days ago
CRITICALRubyGems

Savon::Model evaluates WSDL operation names as Ruby source

Savon::Model evaluates WSDL operation names as Ruby source

savon: 0.9.8 → 2.17.2

5 days agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

mcp: before 0.23.0

6 days agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

mcp: before 0.23.0

6 days agoEPSS 0%
MEDIUMRubyGems

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

mcp: before 0.23.0

6 days agoEPSS 0%
CRITICALRubyGems

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

activestorage: before 7.2.3.2

6 days agoEPSS 2%
HIGHRubyGems

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

mcp: before 0.23.0

6 days agoEPSS 0%
LOWRubyGems

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

msgpack: before 1.8.2

6 days agoEPSS 0%
MODERATERubyGems

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

mcp: before 0.23.0

6 days agoEPSS 0%
LOWRubyGems

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

activerecord-tenanted: before 0.7.0

1 week ago
HIGHRubyGems

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

oauth2: 0.4.0 → 2.0.22

1 week agoEPSS 0%
HIGHRubyGems

Excon does not redact additional sensitive/risky headers when following redirects

Excon does not redact additional sensitive/risky headers when following redirects

excon: before 1.5.0

3 weeks agoEPSS 0%
MEDIUMRubyGems

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: before 4.21.0.rc1

1 month agoEPSS 0%

Tooling for RubyGems

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexMavenNuGetPyPIcrates.ionpm