RubyGems incidents
Recent RubyGems vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
guard-livereload has a directory traversal vulnerability
guard-livereload has a directory traversal vulnerability
guard-livereload: before 2.5.2
Savon::Model evaluates WSDL operation names as Ruby source
Savon::Model evaluates WSDL operation names as Ruby source
savon: 0.9.8 → 2.17.2
MCP Ruby SDK: Ruby SSE Session Poisoning
MCP Ruby SDK: Ruby SSE Session Poisoning
mcp: before 0.23.0
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
mcp: before 0.23.0
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
mcp: before 0.23.0
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
activestorage: before 7.2.3.2
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
mcp: before 0.23.0
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
msgpack: before 1.8.2
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
mcp: before 0.23.0
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
activerecord-tenanted: before 0.7.0
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
oauth2: 0.4.0 → 2.0.22
Excon does not redact additional sensitive/risky headers when following redirects
Excon does not redact additional sensitive/risky headers when following redirects
excon: before 1.5.0
katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: before 4.21.0.rc1
Tooling for RubyGems
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.