RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44312Mediumcss_parser: CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS contentGHSA-V2FC-QM4H-8HQVMediumnokogiri: Nokogiri XSLT transform has a memory leakGHSA-C4RQ-3M3G-8WGXHighnokogiri: Nokogiri CSS selector tokenizer has regular expression backtrackingGHSA-3H96-34P3-XM76Mediumgraphql: GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokensCVE-2026-42257Mediumnet-imap: net-imap vulnerable to command Injection via "raw" arguments to multiple commandsCVE-2026-42258Mediumnet-imap: net-imap vulnerable to command Injection via unvalidated Symbol inputsCVE-2026-42256Mediumnet-imap: net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authenticationCVE-2026-42245Lownet-imap: net-imap has quadratic complexity when reading response literalsCVE-2026-42246Highnet-imap: net-imap vulnerable to STARTTLS stripping via invalid response timingCVE-2026-42205Highavo: Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across ResourcesCVE-2026-41316Higherb: ERB has an @_init deserialization guard bypass via def_module / def_method / def_classGHSA-2WVH-87G2-89HRCriticalopenc3: OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner ToolCVE-2026-42087Criticalopenc3: OpenC3 COSMOS has SQL Injection in QuestDB Time-Series DatabaseCVE-2026-42086Mediumopenc3: OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command SenderCVE-2026-42085Mediumopenc3: OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenamesCVE-2026-42084Highopenc3: OpenC3 COSMOS: Hijacked session token can be used to reset password for persistenceCVE-2026-41493Mediumyard: yard: Possible arbitrary path traversal and file access via yard serverCVE-2026-27820Mediumzlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruptionCVE-2026-41146Highiodine: Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gemCVE-2026-40870Highdecidim-comments: Decidim's comments API allows access to all commentable resourcesCVE-2026-40869Highdecidim-core: Decidim amendments can be accepted or rejected by anyoneGHSA-9PM8-VWC5-W2HMLowfat_free_crm: Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by IDCVE-2026-23891Criticaldecidim-core: Decidim has a cross-site scripting (XSS) in user nameCVE-2026-40069Highbsv-sdk: bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcastsCVE-2026-40070Highbsv-sdk: bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)

Stop the waste.
Protect your environment with Kodem.