RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-PHWJ-RPRQ-35PPLownokogiri: Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`GHSA-WFPW-MMFH-QQ69Lownokogiri: Nokogiri: Possible Use-After-Free in XInclude ProcessingGHSA-P67V-3W7G-WJG7Lownokogiri: Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetimeGHSA-WJV4-X9W8-WM3HLownokogiri: Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node typeGHSA-5PRR-V3J2-97MHMediumnokogiri: Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`GHSA-9CV2-CFXC-V4V2Lownokogiri: Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classesGHSA-8678-W3JW-XFC2Lownokogiri: Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247GHSA-5V8H-3H3Q-446PLownokogiri: Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exceptionCVE-2026-55518Criticalavo: Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege EscalationCVE-2026-12515Mediumkatello: katello: missing repository authorization in content_uploads exposes cross-product content existenceCVE-2026-47242Mediumnet-imap: Net::IMAP: Command Injection via ID command argumentCVE-2026-47241Lownet-imap: Net::IMAP: Denial of Service via incomplete raw argument validationCVE-2026-47240Mediumnet-imap: Net::IMAP: Command Injection via non-synchronizing literal in "raw" argumentCVE-2026-47737Highpuma: Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent ConnectionsCVE-2026-47736Highpuma: Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion GHSA-XF4V-W5X5-PV79Mediumspree: Spree: CSV Formula Injection in Customer ExportCVE-2026-44476Mediumdoorkeeper-openid_connect: Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secretCVE-2026-44587Mediumcarrierwave: CarrierWave has a denylisted_content_type bypass via Unescaped Regex MetacharactersCVE-2026-45363Highjwt: ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351CVE-2026-33637Lowfaraday: Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scopingCVE-2026-44837Mediumview_component: view_component: System Test Entry Point Path Check Allows Sibling Directory EscapeCVE-2026-44836Mediumview_component: view_component: Preview Route Can Dispatch Inherited Helper MethodsCVE-2026-40295Mediumdevise: Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout HandlerCVE-2025-67202Mediumsidekiq-cron: Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URLCVE-2026-44511Highkatalyst-koi: katalyst-koi: Session cookies can be replayed after user logout

Stop the waste.
Protect your environment with Kodem.