RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45573Mediumdecidim-core: Decidim: Push subscriptions can be abused for server-side requestsCVE-2026-45572Mediumdecidim-core: Decidim: HTML content blocks allow stored script executionCVE-2026-45415Mediumdecidim-verifications: Decidim: CSV census record endpoints improper authorizationCVE-2026-45414Highdecidim: Decidim: JWT-backed authentication can be replayed across organizationsCVE-2026-45378Highdecidim-verifications: Decidim: Verification documents can be downloaded through reusable linksCVE-2026-45377Mediumdecidim-core: Decidim: Private exports can be downloaded through reusable linksCVE-2026-45376Mediumdecidim-admin: Decidim: Admin user search allows SQL injection through similarity-based sortingCVE-2026-45330Mediumdecidim-verifications: Decidim: Verification admins can access supplied IDs from other organizationsCVE-2026-45086Mediumdecidim-demographics: Decidim: Forms admin question editor lacks authorizationCVE-2026-54171Mediumexcon: Excon does not redact additional sensitive/risky headers when following redirectsCVE-2026-54163Mediumsecure_headers: Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputCVE-2026-53769Mediumavo: Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policyCVE-2026-53727Highcss_parser: Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`GHSA-MJGF-XJ26-9QF9Highpay: pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifierCVE-2026-49342Mediumyard: YARD static cache reads raw traversal paths before router sanitizationCVE-2026-44163Mediumfluent-plugin-opentelemetry: fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`CVE-2026-44162Lowfluent-plugin-s3: fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`CVE-2026-44161Highfluentd: Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`CVE-2026-44160Highfluentd: Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`CVE-2026-44025Highfluentd: Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent APICVE-2026-44024Criticalfluentd: Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` PlaceholderCVE-2026-54906Lowconcurrent-ruby: Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruptionCVE-2026-54905Lowconcurrent-ruby: Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivityCVE-2026-54904Highconcurrent-ruby: Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`CVE-2026-54903Highoj: Oj: Integer Overflow in Oj.load 2GB String Handling

Stop the waste.
Protect your environment with Kodem.