RubyGems incidents

Recent RubyGems vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

MEDIUMRubyGems

decidim-elections: Election question titles allow stored script execution

decidim-elections: Election question titles allow stored script execution

decidim-elections: before 0.32.0

6 days ago
MEDIUMRubyGems

Mail: Email address spoofing via malformed RFC 2047 encoded-words

Mail: Email address spoofing via malformed RFC 2047 encoded-words

mail: before 2.9.1

1 week ago
UNKNOWNRubyGems

Malicious code in micro-quick-box (RubyGems)

Malicious code in micro-quick-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-quick-box (RubyGems)

Malicious code in nano-quick-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-max-rb (RubyGems)

Malicious code in micro-max-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-sharp-kit (RubyGems)

Malicious code in micro-sharp-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-max-box (RubyGems)

Malicious code in nano-max-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-clean-sys (RubyGems)

Malicious code in mini-clean-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-fast-rb (RubyGems)

Malicious code in piko-fast-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-lite-tool (RubyGems)

Malicious code in hyper-lite-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-sharp-hub (RubyGems)

Malicious code in mega-sharp-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-clean-gem (RubyGems)

Malicious code in micro-clean-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-safe-kit (RubyGems)

Malicious code in hyper-safe-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-quick-tool (RubyGems)

Malicious code in nano-quick-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-sharp-mod (RubyGems)

Malicious code in micro-sharp-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-pro-box (RubyGems)

Malicious code in mega-pro-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-lite-pkg (RubyGems)

Malicious code in micro-lite-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-safe-hub (RubyGems)

Malicious code in mega-safe-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-safe-hub (RubyGems)

Malicious code in hyper-safe-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-fast-box (RubyGems)

Malicious code in piko-fast-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-lite-gem (RubyGems)

Malicious code in piko-lite-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-sharp-lib (RubyGems)

Malicious code in mini-sharp-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-quick-sys (RubyGems)

Malicious code in super-quick-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-sharp-tool (RubyGems)

Malicious code in giga-sharp-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-fast-hub (RubyGems)

Malicious code in ultra-fast-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-sharp-sys (RubyGems)

Malicious code in piko-sharp-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-fast-sys (RubyGems)

Malicious code in mega-fast-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-smart-tool (RubyGems)

Malicious code in mega-smart-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-quick-rb (RubyGems)

Malicious code in mega-quick-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-clean-pkg (RubyGems)

Malicious code in giga-clean-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-lite-kit (RubyGems)

Malicious code in mega-lite-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-fast-hub (RubyGems)

Malicious code in micro-fast-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-max-kit (RubyGems)

Malicious code in giga-max-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-smart-pkg (RubyGems)

Malicious code in mega-smart-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-smart-kit (RubyGems)

Malicious code in hyper-smart-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-clean-kit (RubyGems)

Malicious code in giga-clean-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-sharp-box (RubyGems)

Malicious code in hyper-sharp-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-fast-mod (RubyGems)

Malicious code in micro-fast-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-pro-kit (RubyGems)

Malicious code in hyper-pro-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-smart-sys (RubyGems)

Malicious code in mega-smart-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-max-mod (RubyGems)

Malicious code in giga-max-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-sharp-lib (RubyGems)

Malicious code in hyper-sharp-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-pro-hub (RubyGems)

Malicious code in super-pro-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-safe-pkg (RubyGems)

Malicious code in mega-safe-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-safe-hub (RubyGems)

Malicious code in giga-safe-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-lite-mod (RubyGems)

Malicious code in piko-lite-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-safe-lib (RubyGems)

Malicious code in mini-safe-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-pure-tool (RubyGems)

Malicious code in mega-pure-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-clean-box (RubyGems)

Malicious code in giga-clean-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-pure-kit (RubyGems)

Malicious code in giga-pure-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-sharp-kit (RubyGems)

Malicious code in nano-sharp-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-smart-gem (RubyGems)

Malicious code in nano-smart-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-pro-kit (RubyGems)

Malicious code in mega-pro-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-max-tool (RubyGems)

Malicious code in piko-max-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-smart-sys (RubyGems)

Malicious code in piko-smart-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-clean-sys (RubyGems)

Malicious code in nano-clean-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-lite-hub (RubyGems)

Malicious code in super-lite-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-smart-pkg (RubyGems)

Malicious code in nano-smart-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-safe-tool (RubyGems)

Malicious code in micro-safe-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in circle-w3s (RubyGems)

Malicious code in circle-w3s (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-max-mod (RubyGems)

Malicious code in micro-max-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-lite-rb (RubyGems)

Malicious code in mini-lite-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-quick-mod (RubyGems)

Malicious code in nano-quick-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-pure-tool (RubyGems)

Malicious code in mini-pure-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-pro-pkg (RubyGems)

Malicious code in ultra-pro-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-safe-box (RubyGems)

Malicious code in ultra-safe-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-max-gem (RubyGems)

Malicious code in tiny-max-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-max-sys (RubyGems)

Malicious code in ultra-max-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-max-box (RubyGems)

Malicious code in tiny-max-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-quick-box (RubyGems)

Malicious code in tiny-quick-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-sharp-sys (RubyGems)

Malicious code in super-sharp-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-pro-sys (RubyGems)

Malicious code in tiny-pro-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-pure-gem (RubyGems)

Malicious code in mega-pure-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-pure-mod (RubyGems)

Malicious code in ultra-pure-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-fast-rb (RubyGems)

Malicious code in ultra-fast-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-smart-tool (RubyGems)

Malicious code in ultra-smart-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-smart-sys (RubyGems)

Malicious code in tiny-smart-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-sharp-pkg (RubyGems)

Malicious code in tiny-sharp-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-sharp-lib (RubyGems)

Malicious code in super-sharp-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-pro-rb (RubyGems)

Malicious code in tiny-pro-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-quick-gem (RubyGems)

Malicious code in super-quick-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-quick-hub (RubyGems)

Malicious code in ultra-quick-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-pure-box (RubyGems)

Malicious code in tiny-pure-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-max-pkg (RubyGems)

Malicious code in ultra-max-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-pure-hub (RubyGems)

Malicious code in ultra-pure-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-smart-pkg (RubyGems)

Malicious code in ultra-smart-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-pro-tool (RubyGems)

Malicious code in ultra-pro-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in hyper-quick-kit (RubyGems)

Malicious code in hyper-quick-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-smart-hub (RubyGems)

Malicious code in ultra-smart-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-pro-kit (RubyGems)

Malicious code in ultra-pro-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-safe-sys (RubyGems)

Malicious code in tiny-safe-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-max-gem (RubyGems)

Malicious code in piko-max-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-smart-mod (RubyGems)

Malicious code in tiny-smart-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mega-clean-sys (RubyGems)

Malicious code in mega-clean-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in giga-quick-rb (RubyGems)

Malicious code in giga-quick-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in ultra-sharp-kit (RubyGems)

Malicious code in ultra-sharp-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in super-pure-rb (RubyGems)

Malicious code in super-pure-rb (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in tiny-pro-lib (RubyGems)

Malicious code in tiny-pro-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-smart-box (RubyGems)

Malicious code in nano-smart-box (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in opentelemetry-exporter-otlp-http (RubyGems)

Malicious code in opentelemetry-exporter-otlp-http (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-clean-mod (RubyGems)

Malicious code in piko-clean-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-safe-sys (RubyGems)

Malicious code in nano-safe-sys (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-safe-gem (RubyGems)

Malicious code in mini-safe-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-quick-pkg (RubyGems)

Malicious code in mini-quick-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-sharp-kit (RubyGems)

Malicious code in mini-sharp-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-max-mod (RubyGems)

Malicious code in nano-max-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-safe-mod (RubyGems)

Malicious code in mini-safe-mod (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-pure-lib (RubyGems)

Malicious code in mini-pure-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-smart-pkg (RubyGems)

Malicious code in piko-smart-pkg (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-pure-kit (RubyGems)

Malicious code in micro-pure-kit (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-fast-lib (RubyGems)

Malicious code in nano-fast-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-fast-gem (RubyGems)

Malicious code in piko-fast-gem (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-fast-lib (RubyGems)

Malicious code in mini-fast-lib (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in piko-clean-hub (RubyGems)

Malicious code in piko-clean-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in nano-pure-tool (RubyGems)

Malicious code in nano-pure-tool (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in micro-max-hub (RubyGems)

Malicious code in micro-max-hub (RubyGems)

3 weeks ago
UNKNOWNRubyGems

Malicious code in mini-max-gem (RubyGems)

Malicious code in mini-max-gem (RubyGems)

3 weeks ago
CRITICALRubyGems

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

kobako: 0.1.0 → 0.9.1

4 weeks ago
LOWRubyGems

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

json: 2.20.0 → 2.21.2

1 month ago
MODERATERubyGems

guard-livereload has a directory traversal vulnerability

guard-livereload has a directory traversal vulnerability

guard-livereload: before 2.5.2

1 month ago
CRITICALRubyGems

Savon::Model evaluates WSDL operation names as Ruby source

Savon::Model evaluates WSDL operation names as Ruby source

savon: 0.9.8 → 2.17.2

1 month agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

mcp: before 0.23.0

1 month agoEPSS 0%
MEDIUMRubyGems

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

mcp: before 0.23.0

1 month agoEPSS 0%
MODERATERubyGems

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

mcp: before 0.23.0

1 month agoEPSS 0%
CRITICALRubyGems

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

activestorage: before 7.2.3.2

1 month agoEPSS 2%
LOWRubyGems

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

msgpack: before 1.8.2

1 month agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

mcp: before 0.23.0

1 month agoEPSS 0%
HIGHRubyGems

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

mcp: before 0.23.0

1 month agoEPSS 0%
LOWRubyGems

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

activerecord-tenanted: before 0.7.0

1 month ago
HIGHRubyGems

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

oauth2: 0.4.0 → 2.0.22

1 month agoEPSS 0%
MEDIUMRubyGems

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Ruby json: JSON generator heap buffer overflow when streaming to an IO

json: 2.9.0 → 2.19.9

1 month ago
MEDIUMRubyGems

Loofah: SVG `href` attribute bypasses local-reference restriction

Loofah: SVG `href` attribute bypasses local-reference restriction

loofah: before 2.25.2

1 month ago
MODERATERubyGems

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

rails-html-sanitizer: 1.0.3 → 1.7.1

1 month ago
LOWRubyGems

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

loofah: 2.25.0 → 2.25.2

1 month ago
HIGHRubyGems

websocket-driver-ruby: Denial of service via malformed Host header

websocket-driver-ruby: Denial of service via malformed Host header

websocket-driver: before 0.8.2

1 month ago
LOWRubyGems

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

loofah: 2.25.0 → 2.25.2

1 month ago
MODERATERubyGems

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: before 0.8.1

2 months ago
MODERATERubyGems

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: before 0.8.1

2 months ago
MODERATERubyGems

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

websocket-driver: before 0.8.1

2 months ago
HIGHRubyGems

Excon does not redact additional sensitive/risky headers when following redirects

Excon does not redact additional sensitive/risky headers when following redirects

excon: before 1.5.0

2 months agoEPSS 0%
HIGHRubyGems

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

fluentd: before 1.19.3

2 months ago
HIGHRubyGems

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

fluentd: before 1.19.3

2 months ago
CRITICALRubyGems

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

fluentd: before 1.19.3

2 months ago
MEDIUMRubyGems

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

fluent-plugin-s3: 0.7.0 → 1.8.5

2 months ago
MEDIUMRubyGems

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

fluentd: before 1.19.3

2 months ago
LOWRubyGems

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

nokogiri: before 1.19.4

2 months ago
HIGHRubyGems

Oj: Integer Overflow in Oj.load 2GB String Handling

Oj: Integer Overflow in Oj.load 2GB String Handling

oj: before 3.17.3

2 months ago
MEDIUMRubyGems

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

nokogiri: before 1.19.4

2 months ago
HIGHRubyGems

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

oj: before 3.17.3

2 months ago
HIGHRubyGems

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

oj: before 3.17.3

2 months ago
HIGHRubyGems

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

oj: before 3.17.3

2 months ago
LOWRubyGems

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

nokogiri: before 1.19.4

2 months ago
HIGHRubyGems

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

oj: before 3.17.3

2 months ago
HIGHRubyGems

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

oj: before 3.17.3

2 months ago
LOWRubyGems

Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

concurrent-ruby: before 1.3.7

2 months ago
HIGHRubyGems

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

concurrent-ruby: before 1.3.7

2 months ago
HIGHRubyGems

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

concurrent-ruby: before 1.3.7

2 months ago
HIGHRubyGems

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

oj: before 3.17.3

2 months ago
MEDIUMRubyGems

Oj: intern.c form_attr (uninitialized stack read)

Oj: intern.c form_attr (uninitialized stack read)

oj: before 3.17.3

2 months ago
HIGHRubyGems

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

oj: before 3.17.3

2 months ago
LOWRubyGems

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

nokogiri: before 1.19.4

2 months ago
HIGHRubyGems

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

oj: before 3.17.3

2 months ago
HIGHRubyGems

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

faraday: 2.0.0 → 2.14.3

2 months ago
HIGHRubyGems

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

oj: before 3.17.3

2 months ago
LOWRubyGems

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

nokogiri: before 1.19.4

2 months ago
LOWRubyGems

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

nokogiri: before 1.19.4

2 months ago
MODERATERubyGems

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

nokogiri: before 1.19.4

2 months ago
LOWRubyGems

Nokogiri: Possible Use-After-Free in XInclude Processing

Nokogiri: Possible Use-After-Free in XInclude Processing

nokogiri: before 1.19.4

2 months ago
MEDIUMRubyGems

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: before 4.21.0.rc1

3 months agoEPSS 0%
MODERATERubyGems

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

net-imap: 0.6.0 → 0.6.4.1

3 months ago
LOWRubyGems

Net::IMAP: Denial of Service via incomplete raw argument validation

Net::IMAP: Denial of Service via incomplete raw argument validation

net-imap: 0.6.0 → 0.6.4.1

3 months ago
MODERATERubyGems

Net::IMAP: Command Injection via ID command argument

Net::IMAP: Command Injection via ID command argument

net-imap: 0.6.0 → 0.6.4.1

3 months ago
HIGHRubyGems

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

puma: 8.0.0 → 8.0.2

3 months ago
HIGHRubyGems

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

puma: 8.0.0 → 8.0.2

3 months ago
HIGHRubyGems

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

jwt: 3.0.0 → 3.2.0

4 months ago
LOWRubyGems

Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping

Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping

faraday: 2.0.0 → 2.14.2

4 months ago
HIGHRubyGems

view_component: Preview Route Can Dispatch Inherited Helper Methods

view_component: Preview Route Can Dispatch Inherited Helper Methods

view_component: 3.0.0 → 4.9.0

4 months ago
MEDIUMRubyGems

Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler

Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler

devise: before 5.0.4

4 months ago
HIGHRubyGems

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

view_component: 3.0.0 → 4.9.0

4 months ago
MEDIUMRubyGems

Nokogiri XSLT transform has a memory leak

Nokogiri XSLT transform has a memory leak

nokogiri: before 1.19.3

4 months ago
HIGHRubyGems

Nokogiri CSS selector tokenizer has regular expression backtracking

Nokogiri CSS selector tokenizer has regular expression backtracking

nokogiri: before 1.19.3

4 months ago
LOWRubyGems

net-imap has quadratic complexity when reading response literals

net-imap has quadratic complexity when reading response literals

net-imap: 0.6.0 → 0.6.4

4 months ago
MODERATERubyGems

net-imap vulnerable to command Injection via "raw" arguments to multiple commands

net-imap vulnerable to command Injection via "raw" arguments to multiple commands

net-imap: 0.6.0 → 0.6.4

4 months ago
HIGHRubyGems

net-imap vulnerable to STARTTLS stripping via invalid response timing

net-imap vulnerable to STARTTLS stripping via invalid response timing

net-imap: 0.6.0 → 0.6.4

4 months ago
HIGHRubyGems

net-imap vulnerable to command Injection via unvalidated Symbol inputs

net-imap vulnerable to command Injection via unvalidated Symbol inputs

net-imap: 0.6.0 → 0.6.4

4 months ago
MODERATERubyGems

net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication

net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication

net-imap: 0.6.0 → 0.6.4

4 months ago
CRITICALRubyGems

ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

erb: before 4.0.3.1

4 months ago
HIGHRubyGems

OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool

OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool

openc3: before 7.0.0-rc3

4 months ago
HIGHRubyGems

OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence

OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence

openc3: before 6.10.5

4 months ago
MEDIUMRubyGems

OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames

OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames

openc3: before 6.10.5

4 months ago
CRITICALRubyGems

Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

zlib: 3.2.0 → 3.2.3

5 months ago
CRITICALRubyGems

Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization

Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization

rack-session: 2.0.0 → 2.1.2

5 months ago
HIGHRubyGems

Addressable has a Regular Expression Denial of Service in Addressable templates

Addressable has a Regular Expression Denial of Service in Addressable templates

addressable: 2.3.0 → 2.9.0

5 months ago
HIGHRubyGems

Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads

Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads

rack: before 2.2.23

5 months ago
MEDIUMRubyGems

Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing

Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing

rack: 3.0.0.beta1 → 3.1.21

5 months ago
HIGHRubyGems

Rack::Static prefix matching can expose unintended files under the static root

Rack::Static prefix matching can expose unintended files under the static root

rack: before 2.2.23

5 months ago
MEDIUMRubyGems

Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.

Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.

rack: before 2.2.23

5 months ago
HIGHRubyGems

Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

rack: before 2.2.23

5 months ago
HIGHRubyGems

Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect

Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect

rack: before 2.2.23

5 months ago
MEDIUMRubyGems

Rack's multipart byte range processing allows denial of service via excessive overlapping ranges

Rack's multipart byte range processing allows denial of service via excessive overlapping ranges

rack: before 2.2.23

5 months ago
MEDIUMRubyGems

Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values

Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values

rack: 3.2.0 → 3.2.6

5 months ago
MEDIUMRubyGems

Rack has Content-Length mismatch in Rack::Files error responses

Rack has Content-Length mismatch in Rack::Files error responses

rack: before 2.2.23

5 months ago
MEDIUMRubyGems

Rack:: Static header_rules bypass via URL-encoded paths

Rack:: Static header_rules bypass via URL-encoded paths

rack: before 2.2.23

5 months ago
HIGHRubyGems

Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters

Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters

rack: 3.0.0.beta1 → 3.1.21

5 months ago
MEDIUMRubyGems

Rack::Request accepts invalid Host characters, enabling host allowlist bypass

Rack::Request accepts invalid Host characters, enabling host allowlist bypass

rack: 3.0.0.beta1 → 3.1.21

5 months ago
MEDIUMRubyGems

Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory

Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory

rack: before 2.2.23

5 months ago
LOWRubyGems

Loofah has improper detection of disallowed URIs via `allowed_uri?`

Loofah has improper detection of disallowed URIs via `allowed_uri?`

loofah: 2.25.0 → 2.25.1

5 months ago
HIGHRubyGems

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

activestorage: 8.1.0 → 8.1.2.1

5 months ago
HIGHRubyGems

Rails Active Storage has possible Path Traversal in DiskService

Rails Active Storage has possible Path Traversal in DiskService

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
LOWRubyGems

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

actionpack: 8.1.0 → 8.1.2.1

5 months ago
LOWRubyGems

Rails has a possible XSS vulnerability in its Action View tag helpers

Rails has a possible XSS vulnerability in its Action View tag helpers

actionview: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

activesupport: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Support has a possible DoS vulnerability in its number helpers

Rails Active Support has a possible DoS vulnerability in its number helpers

activesupport: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

activesupport: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Storage has possible glob injection in its DiskService

Rails Active Storage has possible glob injection in its DiskService

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Storage has possible content type bypass via metadata in direct uploads

Rails Active Storage has possible content type bypass via metadata in direct uploads

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
HIGHRubyGems

Ruby JSON has a format string injection vulnerability

Ruby JSON has a format string injection vulnerability

json: 2.18.0 → 2.19.2

6 months ago
LOWRubyGems

Improper detection of disallowed URIs by Loofah `allowed_uri?`

Improper detection of disallowed URIs by Loofah `allowed_uri?`

loofah: 2.25.0 → 2.25.1

6 months ago
UNKNOWNRubyGems

Malicious code in rails_structured_logging (RubyGems)

Malicious code in rails_structured_logging (RubyGems)

6 months ago
MEDIUMRubyGems

Trix has a Stored XSS vulnerability through serialized attributes

Trix has a Stored XSS vulnerability through serialized attributes

action_text-trix: before 2.1.17

6 months ago
MEDIUMRubyGems

Nokogiri does not check the return value from xmlC14NExecute

Nokogiri does not check the return value from xmlC14NExecute

nokogiri: 1.5.1 → 1.19.1

6 months ago
MEDIUMRubyGems

Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href

Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href

rack: before 2.2.22

7 months ago
HIGHRubyGems

Rack has a Directory Traversal via Rack:Directory

Rack has a Directory Traversal via Rack:Directory

rack: before 2.2.22

7 months ago
MEDIUMRubyGems

Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

faraday: 2.0.0 → 2.14.1

7 months ago
HIGHRubyGems

Cassandra Web - Remote File Read

Cassandra Web - Remote File Read

cassandra-web: all versions

7 months ago
HIGHRubyGems

URI Credential Leakage Bypass over CVE-2025-27221

URI Credential Leakage Bypass over CVE-2025-27221

uri: before 0.12.5

8 months ago
HIGHRubyGems

httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage

httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage

httparty: before 0.24.0

8 months ago
HIGHRubyGems

AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue

AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue

aws-sdk-s3: before 1.208.0

9 months ago
MEDIUMRubyGems

Rack has a Possible Information Disclosure Vulnerability

Rack has a Possible Information Disclosure Vulnerability

rack: before 2.2.20

11 months ago
LOWRubyGems

Sinatra is vulnerable to ReDoS through ETag header value generation

Sinatra is vulnerable to ReDoS through ETag header value generation

sinatra: before 4.2.0

11 months ago
HIGHRubyGems

Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing

Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing

rack: before 2.2.20

11 months ago
HIGHRubyGems

Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)

Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)

rack: before 2.2.19

11 months ago
HIGHRubyGems

Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

rack: before 2.2.19

11 months ago
HIGHRubyGems

Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)

Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)

rack: before 2.2.19

11 months ago
HIGHRubyGems

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

rack: before 2.2.18

11 months ago
LOWRubyGems

REXML has DoS condition when parsing malformed XML file

REXML has DoS condition when parsing malformed XML file

rexml: 3.3.3 → 3.4.2

0 years ago
MODERATERubyGems

Active Record logging vulnerable to ANSI escape injection

Active Record logging vulnerable to ANSI escape injection

activerecord: 8.0 → 8.0.2.1

1 year ago
MODERATERubyGems

Ruby SAML DOS vulnerability with large SAML response

Ruby SAML DOS vulnerability with large SAML response

ruby-saml: before 1.18.1

1 year ago
CRITICALRubyGems

Nokogiri patches vendored libxml2 to resolve multiple CVEs

Nokogiri patches vendored libxml2 to resolve multiple CVEs

nokogiri: before 1.18.9

1 year ago
MEDIUMRubyGems

resolv vulnerable to DoS via insufficient DNS domain name length validation

resolv vulnerable to DoS via insufficient DNS domain name length validation

resolv: before 0.2.3

1 year ago
MODERATERubyGems

ReDoS Vulnerability in Rack::Multipart handle_mime_head

ReDoS Vulnerability in Rack::Multipart handle_mime_head

rack: 3.1.0 → 3.1.16

1 year ago
MEDIUMRubyGems

Rack session gets restored after deletion

Rack session gets restored after deletion

rack: before 2.2.14

1 year ago
MEDIUMRubyGems

Rack session gets restored after deletion

Rack session gets restored after deletion

rack-session: 2.0.0 → 2.1.1

1 year ago
HIGHRubyGems

Rack has an Unbounded-Parameter DoS in Rack::QueryParser

Rack has an Unbounded-Parameter DoS in Rack::QueryParser

rack: before 2.2.14

1 year ago
MODERATERubyGems

net-imap rubygem vulnerable to possible DoS by memory exhaustion

net-imap rubygem vulnerable to possible DoS by memory exhaustion

net-imap: 0.5.0 → 0.5.7

1 year ago
LOWRubyGems

Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415

Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415

nokogiri: before 1.18.8

1 year ago
LOWRubyGems

Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction

Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction

publify_core: before 10.0.2

1 year ago
HIGHRubyGems

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

nokogiri: before 1.18.4

1 year ago
HIGHRubyGems

Out-of-bounds Read in Ruby JSON Parser

Out-of-bounds Read in Ruby JSON Parser

json: 2.10.0 → 2.10.2

1 year ago
HIGHRubyGems

Local File Inclusion in Rack::Static

Local File Inclusion in Rack::Static

rack: before 2.2.13

1 year ago
MODERATERubyGems

Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection

Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection

rack: before 2.2.12

1 year ago
MEDIUMRubyGems

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

uri: before 0.11.3

1 year ago
MEDIUMRubyGems

CGI has Denial of Service (DoS) potential in Cookie.parse

CGI has Denial of Service (DoS) potential in Cookie.parse

cgi: before 0.3.5.1

1 year ago
MEDIUMRubyGems

CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement

CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement

cgi: before 0.3.5.1

1 year ago
LOWRubyGems

Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171

Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171

nokogiri: before 1.18.3

1 year ago
HIGHRubyGems

Possible Log Injection in Rack::CommonLogger

Possible Log Injection in Rack::CommonLogger

rack: before 2.2.11

1 year ago
HIGHRubyGems

Possible DoS by memory exhaustion in net-imap

Possible DoS by memory exhaustion in net-imap

net-imap: 0.3.2 → 0.3.8

1 year ago
MEDIUMRubyGems

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

sinatra: before 4.1.0

1 year ago
HIGHRubyGems

REXML ReDoS vulnerability

REXML ReDoS vulnerability

rexml: before 3.3.9

1 year ago
HIGHRubyGems

HTTP Request Smuggling in ruby webrick

HTTP Request Smuggling in ruby webrick

webrick: before 1.8.2

1 year ago
MEDIUMRubyGems

Puma's header normalization allows for client to clobber proxy set headers

Puma's header normalization allows for client to clobber proxy set headers

puma: before 5.6.9

1 year ago
HIGHRubyGems

omniauth-saml vulnerable to Improper Verification of Cryptographic Signature

omniauth-saml vulnerable to Improper Verification of Cryptographic Signature

omniauth-saml: 2.0.0 → 2.1.2

2 years ago
HIGHRubyGems

SAML authentication bypass via Incorrect XPath selector

SAML authentication bypass via Incorrect XPath selector

ruby-saml: before 1.12.3

2 years ago
HIGHRubyGems

REXML denial of service vulnerability

REXML denial of service vulnerability

rexml: before 3.3.6

2 years ago
MEDIUMRubyGems

fugit parse and parse_nat stall on lengthy input

fugit parse and parse_nat stall on lengthy input

fugit: before 1.11.1

2 years ago
HIGHRubyGems

REXML DoS vulnerability

REXML DoS vulnerability

rexml: before 3.3.3

2 years ago
HIGHRubyGems

REXML DoS vulnerability

REXML DoS vulnerability

rexml: before 3.3.3

2 years ago
MEDIUMRubyGems

REXML denial of service vulnerability

REXML denial of service vulnerability

rexml: before 3.3.2

2 years ago
HIGHRubyGems

Decidim cross-site scripting (XSS) in the admin panel

Decidim cross-site scripting (XSS) in the admin panel

decidim-admin: before 0.27.6

2 years ago
HIGHRubyGems

Decidim cross-site scripting (XSS) in the pagination

Decidim cross-site scripting (XSS) in the pagination

decidim: before 0.27.6

2 years ago
MEDIUMRubyGems

Decidim vulnerable to data disclosure through the embed feature

Decidim vulnerable to data disclosure through the embed feature

decidim: before 0.27.6

2 years ago
HIGHRubyGems

RailsAdmin Cross-site Scripting vulnerability in the list view

RailsAdmin Cross-site Scripting vulnerability in the list view

rails_admin: 3.0.0.beta → 3.1.3

2 years ago
MEDIUMRubyGems

Missing security headers in Action Pack on non-HTML responses

Missing security headers in Action Pack on non-HTML responses

actionpack: 6.1.0 → 6.1.7.8

2 years ago
MEDIUMRubyGems

ActionText ContentAttachment can Contain Unsanitized HTML

ActionText ContentAttachment can Contain Unsanitized HTML

actiontext: 7.1.0 → 7.1.3.4

2 years ago
HIGHRubyGems

rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter

rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter

rack-contrib: before 2.5.0

2 years ago
MEDIUMRubyGems

REXML contains a denial of service vulnerability

REXML contains a denial of service vulnerability

rexml: before 3.2.7

2 years ago
LOWRubyGems

Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459

nokogiri: before 1.16.5

2 years ago
HIGHRubyGems

Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values

Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values

phlex: before 1.9.3

2 years ago
HIGHRubyGems

Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags

Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags

phlex: 1.10.0 → 1.10.1

2 years ago
CRITICALRubyGems

StringIO buffer overread vulnerability

StringIO buffer overread vulnerability

stringio: before 3.0.1.1

2 years ago
MEDIUMRubyGems

RDoc RCE vulnerability with .rdoc_options

RDoc RCE vulnerability with .rdoc_options

rdoc: 6.3.3 → 6.3.4.1

2 years ago
CRITICALRubyGems

TurboBoost Commands vulnerable to arbitrary method invocation

TurboBoost Commands vulnerable to arbitrary method invocation

turbo_boost-commands: before 0.1.3

2 years ago
HIGHRubyGems

Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex

Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex

phlex: 1.9.0 → 1.9.1

2 years ago
CRITICALRubyGems

StimulusReflex arbitrary method call

StimulusReflex arbitrary method call

stimulus_reflex: 3.5.0.pre0 → 3.5.0.rc4

2 years ago
MODERATERubyGems

json-jwt allows bypass of identity checks via a sign/encryption confusion attack

json-jwt allows bypass of identity checks via a sign/encryption confusion attack

json-jwt: 1.16.0 → 1.16.6

2 years ago
MEDIUMRubyGems

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

rack: 3.0.0 → 3.0.9.1

2 years ago
LOWRubyGems

Rack has possible DoS Vulnerability with Range Header

Rack has possible DoS Vulnerability with Range Header

rack: 3.0.0 → 3.0.9.1

2 years ago
LOWRubyGems

Rack Header Parsing leads to Possible Denial of Service Vulnerability

Rack Header Parsing leads to Possible Denial of Service Vulnerability

rack: 3.0.0 → 3.0.9.1

2 years ago
MEDIUMRubyGems

YARD's default template vulnerable to Cross-site Scripting in generated frames.html

YARD's default template vulnerable to Cross-site Scripting in generated frames.html

yard: before 0.9.36

2 years ago
LOWRubyGems

Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

actionpack: 7.1.0 → 7.1.3.1

2 years ago
MEDIUMRubyGems

Rails has possible Sensitive Session Information Leak in Active Storage

Rails has possible Sensitive Session Information Leak in Active Storage

activestorage: 5.2.0 → 6.1.7.7

2 years ago
MEDIUMRubyGems

Race condition in Endorsements

Race condition in Endorsements

decidim: 0.10.0 → 0.26.9

2 years ago
HIGHRubyGems

Possible CSRF attack at questionnaire templates preview

Possible CSRF attack at questionnaire templates preview

decidim-templates: 0.23.0 → 0.27.5

2 years ago
HIGHRubyGems

Possibility to circumvent the invitation token expiry period

Possibility to circumvent the invitation token expiry period

decidim: 0.0.1.alpha3 → 0.26.9

2 years ago
MODERATERubyGems

Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062

Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062

nokogiri: 1.16.0 → 1.16.2

2 years ago
MEDIUMRubyGems

Cross-site scripting (XSS) in Action messages on Avo

Cross-site scripting (XSS) in Action messages on Avo

avo: 3.0.0.beta1 → 3.3.0

2 years ago
HIGHRubyGems

avo vulnerable to stored cross-site scripting (XSS) in key_value field

avo vulnerable to stored cross-site scripting (XSS) in key_value field

avo: 3.0.0.beta1 → 3.2.4

2 years ago
HIGHRubyGems

Puma HTTP Request/Response Smuggling vulnerability

Puma HTTP Request/Response Smuggling vulnerability

puma: 6.0.0 → 6.4.2

2 years ago
MEDIUMRubyGems

view_component Cross-site Scripting vulnerability

view_component Cross-site Scripting vulnerability

view_component: 3.0.0 → 3.9.0

2 years ago
HIGHRubyGems

Omniauth::MicrosoftGraph Account takeover (nOAuth)

Omniauth::MicrosoftGraph Account takeover (nOAuth)

omniauth-microsoft_graph: before 2.0.0

2 years ago
HIGHRubyGems

Resque vulnerable to reflected XSS in Queue Endpoint

Resque vulnerable to reflected XSS in Queue Endpoint

resque: before 2.6.0

2 years ago
HIGHRubyGems

Resque vulnerable to Reflected Cross Site Scripting through pathnames

Resque vulnerable to Reflected Cross Site Scripting through pathnames

resque: before 2.1.0

2 years ago
HIGHRubyGems

Decidim has broken access control in templates

Decidim has broken access control in templates

decidim: 0.23.2 → 0.26.8

2 years ago
HIGHRubyGems

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

grpc: 1.56.0 → 1.56.2

3 years ago
HIGHRubyGems

Active Support Possibly Discloses Locally Encrypted Files

Active Support Possibly Discloses Locally Encrypted Files

activesupport: 5.2.0 → 6.1.7.5

3 years ago
CRITICALRubyGems

Puma HTTP Request/Response Smuggling vulnerability

Puma HTTP Request/Response Smuggling vulnerability

puma: before 5.6.7

3 years ago
MEDIUMRubyGems

protocol-http1 HTTP Request/Response Smuggling vulnerability

protocol-http1 HTTP Request/Response Smuggling vulnerability

protocol-http1: before 0.15.1

3 years ago
HIGHRubyGems

Decidim Cross-site Scripting vulnerability in the processes filter

Decidim Cross-site Scripting vulnerability in the processes filter

decidim: 0.14.0 → 0.26.7

3 years ago
MEDIUMRubyGems

Decidim Cross-site Scripting vulnerability in the external link redirections

Decidim Cross-site Scripting vulnerability in the external link redirections

decidim: 0.25.0 → 0.26.7

3 years ago
MEDIUMRubyGems

URI gem has ReDoS vulnerability

URI gem has ReDoS vulnerability

uri: 0.10.1 → 0.10.3

3 years ago
MEDIUMRubyGems

Doorkeeper Improper Authentication vulnerability

Doorkeeper Improper Authentication vulnerability

doorkeeper: before 5.6.6

3 years ago
HIGHRubyGems

avo possible unsafe reflection / partial DoS vulnerability

avo possible unsafe reflection / partial DoS vulnerability

avo: before 2.33.3

3 years ago
HIGHRubyGems

avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields

avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields

avo: before 2.33.3

3 years ago
MEDIUMRubyGems

Sensitive Terraform Output Values Printed At Info Logging Level In Kitchen-Terraform

Sensitive Terraform Output Values Printed At Info Logging Level In Kitchen-Terraform

kitchen-terraform: 7.0.0 → 7.0.1

3 years ago
MODERATERubyGems

Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs

Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs

nokogiri: before 1.14.3

3 years ago
HIGHRubyGems

Ruby URI component ReDoS issue

Ruby URI component ReDoS issue

uri: 0.12.0 → 0.12.1

3 years ago
HIGHRubyGems

Ruby Time component ReDoS issue

Ruby Time component ReDoS issue

time: 0.2.0 → 0.2.2

3 years ago
HIGHRubyGems

unpoly-rails Denial of Service vulnerability

unpoly-rails Denial of Service vulnerability

unpoly-rails: before 2.7.2.2

3 years ago
CRITICALRubyGems

HTTP response splitting in CGI

HTTP response splitting in CGI

cgi: 0.3.0 → 0.3.5

3 years ago
MODERATERubyGems

Update bundled libxml2 to v2.10.3 to resolve multiple CVEs

Update bundled libxml2 to v2.10.3 to resolve multiple CVEs

nokogiri: before 1.13.9

3 years ago
MEDIUMRubyGems

Ember.js Potential XSS Exploit When Binding `tagName` to User-Supplied Data

Ember.js Potential XSS Exploit When Binding `tagName` to User-Supplied Data

ember-source: before 1.0.0.rc1.1

4 years ago
CRITICALRubyGems

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

jmespath: before 1.6.1

4 years ago
HIGHRubyGems

Integer Overflow or Wraparound in libxml2 affects Nokogiri

Integer Overflow or Wraparound in libxml2 affects Nokogiri

nokogiri: before 1.13.5

4 years ago
HIGHRubyGems

Improper one time password handling in devise-two-factor

Improper one time password handling in devise-two-factor

devise-two-factor: before 4.0.2

4 years ago
HIGHRubyGems

Nokogiri affected by zlib's Out-of-bounds Write vulnerability

Nokogiri affected by zlib's Out-of-bounds Write vulnerability

nokogiri: before 1.13.4

4 years ago
HIGHRubyGems

Vulnerable dependencies in Nokogiri

Vulnerable dependencies in Nokogiri

nokogiri: before 1.13.2

4 years ago
CRITICALRubyGems

Buffer overrun in CGI.escape_html

Buffer overrun in CGI.escape_html

cgi: 0.3.0 → 0.3.1

4 years ago
MODERATERubyGems

Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12

Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12

nokogiri: before 1.11.4

5 years ago
MEDIUMRubyGems

Server-side request forgery in CarrierWave

Server-side request forgery in CarrierWave

carrierwave: before 1.3.2

5 years ago
HIGHRubyGems

Command Injection Vulnerability in Mechanize

Command Injection Vulnerability in Mechanize

mechanize: 2.0.0 → 2.7.7

5 years ago
HIGHRubyGems

omniauth-apple allows attacker to fake their email address during authentication

omniauth-apple allows attacker to fake their email address during authentication

omniauth-apple: before 1.0.1

5 years ago
HIGHRubyGems

Authorization bypass in Spree

Authorization bypass in Spree

spree_api: 3.7.0 → 3.7.13

5 years ago
MEDIUMRubyGems

XSS in Action View

XSS in Action View

actionview: before 5.2.4.4

6 years ago
MEDIUMRubyGems

Ability to change order address without triggering address validations in solidus

Ability to change order address without triggering address validations in solidus

solidus_frontend: before 2.8.6

6 years ago
HIGHRubyGems

Missing TLS certificate verification in faye-websocket

Missing TLS certificate verification in faye-websocket

faye-websocket: before 0.11.0

6 years ago
HIGHRubyGems

Directory traversal in Rack::Directory app bundled with Rack

Directory traversal in Rack::Directory app bundled with Rack

rack: before 2.1.3

6 years ago
HIGHRubyGems

Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names

Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names

rack: before 2.1.4

6 years ago
HIGHRubyGems

Cross-Site Scripting in Kaminari

Cross-Site Scripting in Kaminari

kaminari: before 1.2.1

6 years ago
HIGHRubyGems

HTTP Smuggling via Transfer-Encoding Header in Puma

HTTP Smuggling via Transfer-Encoding Header in Puma

puma: before 3.12.6

6 years ago
HIGHRubyGems

HTTP Smuggling via Transfer-Encoding Header in Puma

HTTP Smuggling via Transfer-Encoding Header in Puma

puma: before 3.12.5

6 years ago
HIGHRubyGems

Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper

Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper

doorkeeper: 5.0.0 → 5.0.3

6 years ago
HIGHRubyGems

Authentication and extension bypass in Faye

Authentication and extension bypass in Faye

faye: 0.5.0 → 1.0.4

6 years ago
CRITICALRubyGems

BibTeX-Ruby vulnerable to OS command injection

BibTeX-Ruby vulnerable to OS command injection

bibtex-ruby: before 5.1.0

6 years ago
HIGHRubyGems

XSS/Script injection vulnerability in matestack

XSS/Script injection vulnerability in matestack

matestack-ui-core: before 0.7.4

6 years ago
MEDIUMRubyGems

Directive injection when using dynamic overrides with user input

Directive injection when using dynamic overrides with user input

secure_headers: 6.0.0 → 6.2.0

6 years ago
HIGHRubyGems

Possible Information Leak / Session Hijack Vulnerability in Rack

Possible Information Leak / Session Hijack Vulnerability in Rack

rack: before 1.6.12

6 years ago
HIGHRubyGems

In RubyGem excon, interrupted Persistent Connections May Leak Response Data

In RubyGem excon, interrupted Persistent Connections May Leak Response Data

excon: before 0.71.0

6 years ago
MEDIUMRubyGems

Haml vulnerable to cross-site scripting

Haml vulnerable to cross-site scripting

haml: before 5.0.0

6 years ago
CRITICALRubyGems

Improper Input Validation in simple_form

Improper Input Validation in simple_form

simple_form: before 5.0.0

6 years ago
HIGHRubyGems

Path Traversal vulnerability that affects yard

Path Traversal vulnerability that affects yard

yard: before 0.9.20

7 years ago
MEDIUMRubyGems

Bootstrap Vulnerable to Cross-Site Scripting

Bootstrap Vulnerable to Cross-Site Scripting

bootstrap: before 4.3.1

7 years ago
MEDIUMRubyGems

Bootstrap Cross-site Scripting vulnerability

Bootstrap Cross-site Scripting vulnerability

bootstrap: 4.0.0 → 4.1.2

8 years ago

Tooling for RubyGems

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenNuGetPackagistPubPyPISwiftURLcrates.ionpm