Tagged “rubygems”
CVEs tagged rubygems, newest first.
89 CVEsRSS
CVE-2026-67431HighMCP Ruby SDK: Ruby SSE Session Poisoning
MCP Ruby SDK: Ruby SSE Session Poisoning
GHSA-pmwx-rm49-xv39LowActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
CVE-2026-54659MediumPagy I18n locale option is not validated before being used in a file path
Pagy I18n locale option is not validated before being used in a file path
CVE-2026-54619Lowsqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
CVE-2026-54620Lowsqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
CVE-2026-54605High· 7.2OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…
CVE-2026-54603High· 8.6OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…
CVE-2026-54696Low· 3.7Ruby json: JSON generator heap buffer overflow when streaming to an IO
Ruby json: JSON generator heap buffer overflow when streaming to an IO
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
GHSA-cj75-f6xr-r4g7MediumRails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-8whx-365g-h9vvLowLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
CVE-2026-54171Medium· 6.5excon: Excon: Information disclosure via unstripped sensitive headers during redirects (CVE-2026-54171)
A flaw was found in Excon, a Ruby HTTP client library. The RedirectFollower middleware, responsible for handling redirects, failed to remove sensitive header information when a request was redirected to a new target. This oversight could l…
CVE-2026-54498High· 8.7ViewComponent: around_render HTML-Safety Bypass
ViewComponent: around_render HTML-Safety Bypass
CVE-2026-54497Medium· 6.8ViewComponent: Reused Component Instances Retain Stale Render Context
ViewComponent: Reused Component Instances Retain Stale Render Context
CVE-2026-54463Mediumwebsocket-driver: Memory exhaustion via abuse of protocol length headers
websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
CVE-2026-54465Mediumwebsocket-driver: Memory exhaustion in HTTP header parser
websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-54163Medium· 4.7Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
CVE-2026-53727HighRuby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
GHSA-mjgf-xj26-9qf9High· 7.4pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
CVE-2026-49342Medium· 5.3YARD static cache reads raw traversal paths before router sanitization
YARD static cache reads raw traversal paths before router sanitization
CVE-2026-44024Critical· 9.8PoCFluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVE-2026-44025High· 7.5Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
CVE-2026-44160High· 7.5Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
CVE-2026-44161High· 7.2Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
GHSA-5v8h-3h3q-446pLowNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
GHSA-8678-w3jw-xfc2Low· 2.6Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
GHSA-9cv2-cfxc-v4v2LowNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
GHSA-5prr-v3j2-97mhMediumNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`