RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-1000305Mediumguard-livereload: guard-livereload has a directory traversal vulnerabilityCVE-2026-53510Highsavon: Savon::Model evaluates WSDL operation names as Ruby sourceCVE-2026-66066Criticalactivestorage: Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processingCVE-2026-54522Lowmsgpack: MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer DisclosureCVE-2026-67431Highmcp: MCP Ruby SDK: Ruby SSE Session PoisoningCVE-2026-67432Highmcp: MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransportCVE-2026-67430Mediummcp: MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodCVE-2026-63119Mediummcp: MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)CVE-2026-63118Mediummcp: MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectionGHSA-PMWX-RM49-XV39Lowactiverecord-tenanted: ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversalCVE-2026-54659Mediumpagy: Pagy I18n locale option is not validated before being used in a file pathCVE-2026-54603Highoauth2: OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker hostCVE-2026-54605Highoauth: OAuth: Cross-origin token-request redirects can expose signed request metadataCVE-2026-54620Lowsqlite3-ruby: sqlite3-ruby has Use-After-Free in SQLite Aggregate Function CallbacksCVE-2026-54619Lowsqlite3-ruby: sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different ArityGHSA-53G2-MVCC-Q9X3Mediumtrix: Trix: Stored XSS via HTMLParser attribute injection on pasteCVE-2026-54696Lowjson: Ruby json: JSON generator heap buffer overflow when streaming to an IOGHSA-CJ75-F6XR-R4G7Mediumrails-html-sanitizer: Rails HTML Sanitizers: Possible XSS vulnerability with certain configurationsGHSA-5QHF-9PHG-95M2Lowloofah: Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolonsGHSA-9WJQ-CP2P-HRGFMediumloofah: Loofah: SVG `href` attribute bypasses local-reference restrictionCVE-2026-61666Highwebsocket-driver: websocket-driver-ruby: Denial of service via malformed Host headerGHSA-8WHX-365G-H9VVLowloofah: Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character referencesCVE-2026-50276Highdatadog: dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoSCVE-2026-54497Mediumview_component: ViewComponent: Reused Component Instances Retain Stale Render ContextCVE-2026-54498Highview_component: ViewComponent: around_render HTML-Safety Bypass

Stop the waste.
Protect your environment with Kodem.