VulnSea

Tagged “rubygems”

CVEs tagged rubygems, newest first.

89 CVEsRSS

CVE-2026-67431High
1mo ago

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

▾ Twilightmcp · mcpEPSS 0.48%via GHSA
GHSA-pmwx-rm49-xv39Low
2mo ago

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

▾ Sunlitactiverecord-tenanted · activerecord-tenantedvia GHSA
CVE-2026-54659Medium
2mo ago

Pagy I18n locale option is not validated before being used in a file path

Pagy I18n locale option is not validated before being used in a file path

▾ Sunlitpagy · pagyEPSS 0.54%via GHSA
CVE-2026-54619Low
2mo ago

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

▾ Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.14%via GHSA
CVE-2026-54620Low
2mo ago

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

▾ Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.14%via GHSA
CVE-2026-54605High· 7.2
2mo ago

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…

▾ Twilightoauth · oauthEPSS 0.19%via NVD
CVE-2026-54603High· 8.6
2mo ago

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…

▾ Twilightoauth2 · oauth2EPSS 0.59%via NVD
CVE-2026-54696Low· 3.7
2mo ago

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Ruby json: JSON generator heap buffer overflow when streaming to an IO

▾ Sunlitjson · jsonEPSS 0.38%via GHSA
GHSA-9wjq-cp2p-hrgfMedium· 4.7
2mo ago

Loofah: SVG `href` attribute bypasses local-reference restriction

Loofah: SVG `href` attribute bypasses local-reference restriction

▾ Sunlitloofah · loofahvia GHSA
GHSA-5qhf-9phg-95m2Low
2mo ago

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

▾ Sunlitloofah · loofahvia GHSA
GHSA-cj75-f6xr-r4g7Medium
2mo ago

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

▾ Sunlitrails-html-sanitizer · rails-html-sanitizervia GHSA
GHSA-8whx-365g-h9vvLow
2mo ago

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

▾ Sunlitloofah · loofahvia GHSA
CVE-2026-54171Medium· 6.5
2mo ago

excon: Excon: Information disclosure via unstripped sensitive headers during redirects (CVE-2026-54171)

A flaw was found in Excon, a Ruby HTTP client library. The RedirectFollower middleware, responsible for handling redirects, failed to remove sensitive header information when a request was redirected to a new target. This oversight could l…

▾ SunlitRed Hat · Red Hat 3scale API Management Platform 2EPSS 0.43%via CSAF
CVE-2026-54498High· 8.7
2mo ago

ViewComponent: around_render HTML-Safety Bypass

ViewComponent: around_render HTML-Safety Bypass

▾ Twilightview_component · view_componentEPSS 0.45%via GHSA
CVE-2026-54497Medium· 6.8
2mo ago

ViewComponent: Reused Component Instances Retain Stale Render Context

ViewComponent: Reused Component Instances Retain Stale Render Context

▾ Sunlitview_component · view_componentEPSS 0.33%via GHSA
CVE-2026-54463Medium
2mo ago

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: Memory exhaustion via abuse of protocol length headers

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.49%via GHSA
CVE-2026-54464Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
CVE-2026-54465Medium
2mo ago

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: Memory exhaustion in HTTP header parser

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.49%via GHSA
CVE-2026-54163Medium· 4.7
2mo ago

Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input

Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input

▾ Sunlitsecure_headers · secure_headersEPSS 0.29%via GHSA
CVE-2026-53727High
2mo ago

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

▾ Twilightcss_parser · css_parserEPSS 0.51%via GHSA
GHSA-mjgf-xj26-9qf9High· 7.4
2mo ago

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

▾ Twilightpay · payvia GHSA
CVE-2026-49342Medium· 5.3
3mo ago

YARD static cache reads raw traversal paths before router sanitization

YARD static cache reads raw traversal paths before router sanitization

▾ Sunlityard · yardEPSS 0.40%via GHSA
CVE-2026-44024Critical· 9.8PoC
3mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-44025High· 7.5
3mo ago

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

▾ Twilightfluentd · fluentdEPSS 0.47%via GHSA
CVE-2026-44160High· 7.5
3mo ago

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

▾ Twilightfluentd · fluentdEPSS 0.62%via GHSA
CVE-2026-44161High· 7.2
3mo ago

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

▾ Twilightfluentd · fluentdEPSS 0.44%via GHSA
GHSA-5v8h-3h3q-446pLow
3mo ago

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-9cv2-cfxc-v4v2Low
3mo ago

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-5prr-v3j2-97mhMedium
3mo ago

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

▾ Sunlitnokogiri · nokogirivia GHSA
CVEs tagged “rubygems” — page 2 · VulnSea