RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53727Highcss_parser: Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`GHSA-MJGF-XJ26-9QF9Highpay: pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifierCVE-2026-49342Mediumyard: YARD static cache reads raw traversal paths before router sanitizationCVE-2026-44163Mediumfluent-plugin-opentelemetry: fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`CVE-2026-44162Lowfluent-plugin-s3: fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`CVE-2026-44161Highfluentd: Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`CVE-2026-44160Highfluentd: Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`CVE-2026-44025Highfluentd: Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent APICVE-2026-44024Criticalfluentd: Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` PlaceholderCVE-2026-54906Lowconcurrent-ruby: Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruptionCVE-2026-54905Lowconcurrent-ruby: Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivityCVE-2026-54904Highconcurrent-ruby: Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`CVE-2026-54903Highoj: Oj: Integer Overflow in Oj.load 2GB String HandlingCVE-2026-54902Highoj: Oj: Use-After-Free in Oj::Parser SAJ Long Key CallbackCVE-2026-54901Highoj: Oj: Use-After-Free in Oj::Parser array_class/hash_class GC MarkingCVE-2026-54900Highoj: Oj: Negative-Size memcpy in Oj::Parser create_id Attribute HandlingCVE-2026-54898Highoj: Oj: Use-After-Free in Oj::Parser SAJ Callback via Input MutationCVE-2026-54897Highoj: Oj: Use-After-Free in Oj::Doc Iterators via Reentrant CloseCVE-2026-54896Highoj: Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large IndentCVE-2026-54592Highoj: Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputCVE-2026-54500Mediumoj: Oj: intern.c form_attr (uninitialized stack read)CVE-2026-54297Highfaraday: Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parametersCVE-2026-54502Highoj: Oj: Stack Buffer Overflow in Oj.dump via Large IndentCVE-2026-54899Highoj: Oj: Use-After-Free in Oj::Parser Symbol Key Cache ToggleGHSA-MQQ5-J7W8-2HGHHighalchemy_cms: AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

Stop the waste.
Protect your environment with Kodem.