RubyGems incidents

Recent RubyGems vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

CRITICALRubyGems

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

kobako: 0.1.0 → 0.9.1

4 days ago
LOWRubyGems

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

json: 2.20.0 → 2.21.2

2 weeks ago
MODERATERubyGems

guard-livereload has a directory traversal vulnerability

guard-livereload has a directory traversal vulnerability

guard-livereload: before 2.5.2

3 weeks ago
CRITICALRubyGems

Savon::Model evaluates WSDL operation names as Ruby source

Savon::Model evaluates WSDL operation names as Ruby source

savon: 0.9.8 → 2.17.2

3 weeks agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

mcp: before 0.23.0

3 weeks agoEPSS 0%
MEDIUMRubyGems

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

mcp: before 0.23.0

3 weeks agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

mcp: before 0.23.0

3 weeks agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

mcp: before 0.23.0

3 weeks agoEPSS 0%
MODERATERubyGems

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

mcp: before 0.23.0

3 weeks agoEPSS 0%
LOWRubyGems

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

msgpack: before 1.8.2

3 weeks agoEPSS 0%
CRITICALRubyGems

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

activestorage: before 7.2.3.2

3 weeks agoEPSS 2%
LOWRubyGems

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

activerecord-tenanted: before 0.7.0

3 weeks ago
HIGHRubyGems

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

oauth2: 0.4.0 → 2.0.22

3 weeks agoEPSS 0%
LOWRubyGems

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

loofah: 2.25.0 → 2.25.2

4 weeks ago
MODERATERubyGems

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

rails-html-sanitizer: 1.0.3 → 1.7.1

4 weeks ago
MEDIUMRubyGems

Loofah: SVG `href` attribute bypasses local-reference restriction

Loofah: SVG `href` attribute bypasses local-reference restriction

loofah: before 2.25.2

4 weeks ago
LOWRubyGems

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

loofah: 2.25.0 → 2.25.2

4 weeks ago
MODERATERubyGems

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: before 0.8.1

1 month ago
MODERATERubyGems

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

websocket-driver: before 0.8.1

1 month ago
MODERATERubyGems

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: before 0.8.1

1 month ago
HIGHRubyGems

Excon does not redact additional sensitive/risky headers when following redirects

Excon does not redact additional sensitive/risky headers when following redirects

excon: before 1.5.0

1 month agoEPSS 0%
HIGHRubyGems

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

concurrent-ruby: before 1.3.7

2 months ago
MEDIUMRubyGems

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: before 4.21.0.rc1

2 months agoEPSS 0%
MEDIUMRubyGems

Trix has a Stored XSS vulnerability through serialized attributes

Trix has a Stored XSS vulnerability through serialized attributes

action_text-trix: before 2.1.17

5 months ago
HIGHRubyGems

omniauth-saml vulnerable to Improper Verification of Cryptographic Signature

omniauth-saml vulnerable to Improper Verification of Cryptographic Signature

omniauth-saml: 2.0.0 → 2.1.2

1 year ago
HIGHRubyGems

SAML authentication bypass via Incorrect XPath selector

SAML authentication bypass via Incorrect XPath selector

ruby-saml: before 1.12.3

1 year ago
MEDIUMRubyGems

fugit parse and parse_nat stall on lengthy input

fugit parse and parse_nat stall on lengthy input

fugit: before 1.11.1

2 years ago
LOWRubyGems

Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

nokogiri: before 1.16.5

2 years ago
MODERATERubyGems

Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062

Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062

nokogiri: 1.16.0 → 1.16.2

2 years ago
CRITICALRubyGems

HTTP response splitting in CGI

HTTP response splitting in CGI

cgi: 0.3.0 → 0.3.5

3 years ago
CRITICALRubyGems

Buffer overrun in CGI.escape_html

Buffer overrun in CGI.escape_html

cgi: 0.3.0 → 0.3.1

4 years ago

Tooling for RubyGems

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexMavenNuGetPackagistPyPIcrates.ionpm