RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-39324Criticalrack-session: Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationCVE-2026-35611Highaddressable: Addressable has a Regular Expression Denial of Service in Addressable templatesCVE-2026-35201Mediumrdiscount: rdiscount has an Out-of-bounds ReadCVE-2026-34835Mediumrack: Rack::Request accepts invalid Host characters, enabling host allowlist bypassCVE-2026-34831Mediumrack: Rack has Content-Length mismatch in Rack::Files error responsesCVE-2026-34830Mediumrack: Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-RedirectCVE-2026-34829Highrack: Rack's multipart parsing without Content-Length header allows unbounded chunked file uploadsCVE-2026-34763Mediumrack: Rack has a root directory disclosure via unescaped regex interpolation in Rack::DirectoryCVE-2026-34230Highrack: Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding headerCVE-2026-32762Mediumrack: Rack: Forwarded Header semicolon injection enables Host and Scheme spoofingCVE-2026-26962Mediumrack: Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter valuesCVE-2026-26961Mediumrack: Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.CVE-2026-34827Highrack: Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parametersCVE-2026-34826Mediumrack: Rack's multipart byte range processing allows denial of service via excessive overlapping rangesCVE-2026-34786Mediumrack: Rack:: Static header_rules bypass via URL-encoded pathsCVE-2026-34785Highrack: Rack::Static prefix matching can expose unintended files under the static rootGHSA-53P3-C7VP-4MCCLowtrix: Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)CVE-2026-34060Highruby-lsp: Ruby LSP has arbitrary code execution through branch settingCVE-2026-33946Highmcp: MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID ReplayGHSA-2J22-PR5W-6GQ8Lowloofah: Loofah has improper detection of disallowed URIs via `allowed_uri?`CVE-2026-33658Lowactivestorage: Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requestsCVE-2026-33635Mediumicalendar: iCalendar has ICS injection via unsanitized URI property valuesCVE-2026-33202Mediumactivestorage: Rails Active Storage has possible glob injection in its DiskServiceCVE-2026-33195Highactivestorage: Rails Active Storage has possible Path Traversal in DiskServiceCVE-2026-33176Mediumactivesupport: Rails Active Support has a possible DoS vulnerability in its number helpers

Stop the waste.
Protect your environment with Kodem.