VulnSea

Tagged “rubygems”

CVEs tagged rubygems, newest first.

85 CVEsRSS

CVE-2026-44282Medium· 4.8
6d ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_titl…

Sunlitdecidim · decidimEPSS 0.37%via NVD
CVE-2026-44163Medium· 5.3
6d ago

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory with…

Sunlitfluent-plugins-nursery · fluent-plugin-opentelemetryEPSS 0.34%via NVD
CVE-2026-50276High· 7.5
1w ago

dd-trace-rb is Datadog's client library for Ruby

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…

TwilightDataDog · dd-trace-rbEPSS 0.76%via NVD
CVE-2026-44162Low· 2.7
1w ago

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_l…

Sunlitfluent · fluent-plugin-s3EPSS 0.35%via NVD
CVE-2026-53769Medium· 6.5PoC
2w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

Twilightavo-hq · avoEPSS 0.25%via NVD
CVE-2026-63435Medium· 5.3
2w ago

Mail is an internet library for Ruby designed to handle email generation, parsing, and sending

Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy charset cap…

Sunlitmail · mailEPSS 0.33%via NVD
CVE-2026-55107Critical· 10.0
1mo ago

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

Midnightkobako · kobakovia GHSA
CVE-2026-61666High· 7.5
1mo ago

websocket-driver is a WebSocket protocol handler with pluggable I/O

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing …

Twilightwebsocket-driver · websocket-driverEPSS 0.34%via NVD
CVE-2026-71847Low
1mo ago

Ruby JSON is a JSON implementation for Ruby

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released stora…

Sunlitjson · jsonEPSS 0.39%via NVD
CVE-2026-45378High· 7.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Act…

Twilightdecidim-verifications · decidim-verificationsEPSS 0.30%via NVD
CVE-2026-45414High· 8.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …

Twilightdecidim · decidimEPSS 0.32%via NVD
CVE-2026-45415Medium· 6.0
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorizatio…

Sunlitdecidim-verifications · decidim-verificationsEPSS 0.46%via NVD
CVE-2026-45572Medium· 4.8
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML con…

Sunlitdecidim-core · decidim-coreEPSS 0.18%via NVD
CVE-2026-45573Medium· 6.4
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint wi…

Sunlitdecidim-core · decidim-coreEPSS 0.31%via NVD
CVE-2016-1000305Medium
1mo ago

guard-livereload has a directory traversal vulnerability

guard-livereload has a directory traversal vulnerability

Sunlitguard-livereload · guard-livereloadvia GHSA
CVE-2026-53510High· 8.1
1mo ago

Savon is a Ruby SOAP client

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. Thi…

Twilightsavon · savonEPSS 0.42%via NVD
CVE-2026-45086Medium· 5.4
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor w…

Sunlitdecidim-demographics · decidim-demographicsEPSS 0.17%via NVD
CVE-2026-45330Medium· 4.9
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier wi…

Sunlitdecidim-verifications · decidim-verificationsEPSS 0.35%via NVD
CVE-2026-45376Medium· 5.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity ex…

Sunlitdecidim-admin · decidim-adminEPSS 0.34%via NVD
CVE-2026-45377Medium· 6.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resul…

Sunlitdecidim-core · decidim-coreEPSS 0.27%via NVD
CVE-2026-66066CriticalPoC
1mo ago

Action Pack is a framework for handling and responding to web requests

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload …

Abyssalactivestorage · activestorageEPSS 28%via NVD
CVE-2026-54522Low
1mo ago

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

Sunlitmsgpack · msgpackEPSS 0.16%via GHSA
CVE-2026-63118Medium
1mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

Sunlitmcp · mcpEPSS 0.19%via GHSA
CVE-2026-63119Medium· 6.2
1mo ago

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

Sunlitmcp · mcpEPSS 0.13%via GHSA
CVE-2026-67430Medium· 5.3
1mo ago

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

Sunlitmcp · mcpEPSS 0.31%via GHSA
CVE-2026-67432High· 7.5
1mo ago

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

Twilightmcp · mcpEPSS 0.43%via GHSA
CVE-2026-67431High
1mo ago

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

Twilightmcp · mcpEPSS 0.29%via GHSA
GHSA-pmwx-rm49-xv39Low
1mo ago

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

Sunlitactiverecord-tenanted · activerecord-tenantedvia GHSA
CVE-2026-54659Medium
1mo ago

Pagy I18n locale option is not validated before being used in a file path

Pagy I18n locale option is not validated before being used in a file path

Sunlitpagy · pagyEPSS 0.37%via GHSA
CVE-2026-54619Low
1mo ago

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.11%via GHSA
CVEs tagged “rubygems” · VulnSea