Tagged “rubygems”
CVEs tagged rubygems, newest first.
89 CVEsRSS
GHSA-wjv4-x9w8-wm3hLowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
GHSA-p67v-3w7g-wjg7LowNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
GHSA-wfpw-mmfh-qq69LowNokogiri: Possible Use-After-Free in XInclude Processing
Nokogiri: Possible Use-After-Free in XInclude Processing
GHSA-phwj-rprq-35ppLowNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
GHSA-mqq5-j7w8-2hghHigh· 7.5AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
CVE-2026-54899HighOj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-54502HighOj: Stack Buffer Overflow in Oj.dump via Large Indent
Oj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-54297High· 7.5Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
CVE-2026-54500Medium· 5.3Oj: intern.c form_attr (uninitialized stack read)
Oj: intern.c form_attr (uninitialized stack read)
CVE-2026-54592High· 7.5Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2026-54896HighOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
CVE-2026-54897HighOj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
CVE-2026-54898HighOj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
CVE-2026-54900HighPoCOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-54901HighOj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-54902HighOj: Use-After-Free in Oj::Parser SAJ Long Key Callback
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-54903HighOj: Integer Overflow in Oj.load 2GB String Handling
Oj: Integer Overflow in Oj.load 2GB String Handling
CVE-2026-54904HighConcurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
CVE-2026-54905LowConcurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
CVE-2026-54906LowConcurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
CVE-2026-12515Medium· 4.3katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: missing repository authorization in content_uploads exposes cross-product content existence
CVE-2026-55518Critical· 9.6Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
CVE-2026-47737High· 7.5Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVE-2026-47240MediumNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-47241LowNet::IMAP: Denial of Service via incomplete raw argument validation
Net::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-47242MediumNet::IMAP: Command Injection via ID command argument
Net::IMAP: Command Injection via ID command argument
CVE-2026-47736High· 7.5Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
CVE-2020-36939High· 7.5PoCCassandra Web - Remote File Read
Cassandra Web - Remote File Read
CVE-2023-4785High· 7.5Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)