RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-73491Lowloofah: Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character referencesCVE-2026-50276Highdatadog: dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoSCVE-2026-54497Mediumview_component: ViewComponent: Reused Component Instances Retain Stale Render ContextCVE-2026-54498Highview_component: ViewComponent: around_render HTML-Safety BypassCVE-2026-54465Mediumwebsocket-driver: websocket-driver: Memory exhaustion in HTTP header parserCVE-2026-54464Mediumwebsocket-driver: websocket-driver: Resource limit bypass via message compressionCVE-2026-54463Mediumwebsocket-driver: websocket-driver: Memory exhaustion via abuse of protocol length headersCVE-2026-45573Mediumdecidim-core: Decidim: Push subscriptions can be abused for server-side requestsCVE-2026-45572Mediumdecidim-core: Decidim: HTML content blocks allow stored script executionCVE-2026-45415Mediumdecidim-verifications: Decidim: CSV census record endpoints improper authorizationCVE-2026-45414Highdecidim: Decidim: JWT-backed authentication can be replayed across organizationsCVE-2026-45378Highdecidim-verifications: Decidim: Verification documents can be downloaded through reusable linksCVE-2026-45377Mediumdecidim-core: Decidim: Private exports can be downloaded through reusable linksCVE-2026-45376Mediumdecidim-admin: Decidim: Admin user search allows SQL injection through similarity-based sortingCVE-2026-45330Mediumdecidim-verifications: Decidim: Verification admins can access supplied IDs from other organizationsCVE-2026-45086Mediumdecidim-demographics: Decidim: Forms admin question editor lacks authorizationCVE-2026-54171Mediumexcon: Excon does not redact additional sensitive/risky headers when following redirectsCVE-2026-54163Mediumsecure_headers: Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputCVE-2026-53769Mediumavo: Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policyCVE-2026-53727Highcss_parser: Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`GHSA-MJGF-XJ26-9QF9Highpay: pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifierCVE-2026-49342Mediumyard: YARD static cache reads raw traversal paths before router sanitizationCVE-2026-44163Mediumfluent-plugin-opentelemetry: fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`CVE-2026-44162Lowfluent-plugin-s3: fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`CVE-2026-44161Highfluentd: Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Stop the waste.
Protect your environment with Kodem.