VulnSea

Tagged “rubygems”

CVEs tagged rubygems, newest first.

89 CVEsRSS

GHSA-wjv4-x9w8-wm3hLow
3mo ago

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-p67v-3w7g-wjg7Low
3mo ago

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-wfpw-mmfh-qq69Low
3mo ago

Nokogiri: Possible Use-After-Free in XInclude Processing

Nokogiri: Possible Use-After-Free in XInclude Processing

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-phwj-rprq-35ppLow
3mo ago

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-mqq5-j7w8-2hghHigh· 7.5
3mo ago

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

▾ Twilightalchemy_cms · alchemy_cmsvia GHSA
CVE-2026-54899High
3mo ago

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54502High
3mo ago

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54297High· 7.5
3mo ago

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

▾ Twilightfaraday · faradayEPSS 0.76%via GHSA
CVE-2026-54500Medium· 5.3
3mo ago

Oj: intern.c form_attr (uninitialized stack read)

Oj: intern.c form_attr (uninitialized stack read)

▾ Sunlitoj · ojEPSS 0.33%via GHSA
CVE-2026-54592High· 7.5
3mo ago

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

▾ Twilightoj · ojEPSS 0.46%via GHSA
CVE-2026-54896High
3mo ago

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54897High
3mo ago

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54898High
3mo ago

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54900HighPoC
3mo ago

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

▾ Midnightoj · ojEPSS 0.43%via GHSA
CVE-2026-54901High
3mo ago

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54902High
3mo ago

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54903High
3mo ago

Oj: Integer Overflow in Oj.load 2GB String Handling

Oj: Integer Overflow in Oj.load 2GB String Handling

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54904High
3mo ago

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

▾ Twilightconcurrent-ruby · concurrent-rubyEPSS 0.67%via GHSA
CVE-2026-54905Low
3mo ago

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

▾ Sunlitconcurrent-ruby · concurrent-rubyEPSS 0.15%via GHSA
CVE-2026-54906Low
3mo ago

Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

▾ Sunlitconcurrent-ruby · concurrent-rubyEPSS 0.25%via GHSA
CVE-2026-12515Medium· 4.3
3mo ago

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

▾ Sunlitkatello · katelloEPSS 0.22%via GHSA
CVE-2026-55518Critical· 9.6
3mo ago

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

▾ Midnightavo · avoEPSS 0.45%via GHSA
CVE-2026-47737High· 7.5
3mo ago

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

▾ Twilightpuma · pumaEPSS 0.27%via GHSA
CVE-2026-47240Medium
3mo ago

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

▾ Sunlitnet-imap · net-imapEPSS 0.83%via GHSA
CVE-2026-47241Low
3mo ago

Net::IMAP: Denial of Service via incomplete raw argument validation

Net::IMAP: Denial of Service via incomplete raw argument validation

▾ Sunlitnet-imap · net-imapEPSS 0.38%via GHSA
CVE-2026-47242Medium
3mo ago

Net::IMAP: Command Injection via ID command argument

Net::IMAP: Command Injection via ID command argument

▾ Sunlitnet-imap · net-imapEPSS 0.18%via GHSA
CVE-2026-47736High· 7.5
3mo ago

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

▾ Twilightpuma · pumaEPSS 0.63%via GHSA
CVE-2020-36939High· 7.5PoC
8mo ago

Cassandra Web - Remote File Read

Cassandra Web - Remote File Read

▾ Midnightcassandra-web · cassandra-webEPSS 2.9%via GHSA
CVE-2023-4785High· 7.5
3y ago

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

▾ Twilightgrpc · grpcEPSS 0.77%via OSV
CVEs tagged “rubygems” — page 3 · VulnSea