RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44282Mediumdecidim-elections: decidim-elections: Election question titles allow stored script executionCVE-2026-63435Mediummail: Mail: Email address spoofing via malformed RFC 2047 encoded-wordsCVE-2026-55107Criticalkobako: kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)CVE-2026-71847Lowjson: Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsCVE-2016-1000305Mediumguard-livereload: guard-livereload has a directory traversal vulnerabilityCVE-2026-53510Highsavon: Savon::Model evaluates WSDL operation names as Ruby sourceCVE-2026-66066Criticalactivestorage: Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processingCVE-2026-54522Lowmsgpack: MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer DisclosureCVE-2026-67431Highmcp: MCP Ruby SDK: Ruby SSE Session PoisoningCVE-2026-67432Highmcp: MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransportCVE-2026-67430Mediummcp: MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodCVE-2026-63119Mediummcp: MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)CVE-2026-63118Mediummcp: MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectionGHSA-PMWX-RM49-XV39Lowactiverecord-tenanted: ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversalCVE-2026-54659Mediumpagy: Pagy I18n locale option is not validated before being used in a file pathCVE-2026-54603Highoauth2: OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker hostCVE-2026-54605Highoauth: OAuth: Cross-origin token-request redirects can expose signed request metadataCVE-2026-54620Lowsqlite3-ruby: sqlite3-ruby has Use-After-Free in SQLite Aggregate Function CallbacksCVE-2026-54619Lowsqlite3-ruby: sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different ArityCVE-2026-73428Mediumtrix: Trix: Stored XSS via HTMLParser attribute injection on pasteCVE-2026-54696Lowjson: Ruby json: JSON generator heap buffer overflow when streaming to an IOCVE-2026-73648Mediumrails-html-sanitizer: Rails HTML Sanitizers: Possible XSS vulnerability with certain configurationsGHSA-5QHF-9PHG-95M2Lowloofah: Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolonsCVE-2026-73490Mediumloofah: Loofah: SVG `href` attribute bypasses local-reference restrictionCVE-2026-61666Highwebsocket-driver: websocket-driver-ruby: Denial of service via malformed Host header

Stop the waste.
Protect your environment with Kodem.