RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33174Mediumactivestorage: Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requestsCVE-2026-33173Mediumactivestorage: Rails Active Storage has possible content type bypass via metadata in direct uploadsCVE-2026-33170Mediumactivesupport: Rails Active Support has a possible XSS vulnerability in SafeBuffer#%CVE-2026-33169Mediumactivesupport: Rails Active Support has a possible ReDoS vulnerability in number_to_delimitedCVE-2026-33168Lowactionview: Rails has a possible XSS vulnerability in its Action View tag helpersCVE-2026-33167Lowactionpack: Rails has a possible XSS vulnerability in its Action Pack debug exceptionsCVE-2026-33286Criticalgraphiti: Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship NamesCVE-2026-33306Mediumbcrypt: bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRubyCVE-2026-33210Highjson: Ruby JSON has a format string injection vulnerabilityCVE-2026-33209Mediumavo: Avo has a XSS vulnerability on `return_to` paramGHSA-46FP-8F5P-PF2MLowloofah: Improper detection of disallowed URIs by Loofah `allowed_uri?`CVE-2026-32700Mediumdevise: Devise has a confirmable "change email" race condition permits user to confirm email they have no access toCVE-2026-4324Mediumkatello: Katello: Denial of Service and potential information disclosure via SQL injectionGHSA-QMPG-8XG6-PH5QMediumaction_text-trix: Trix has a Stored XSS vulnerability through serialized attributesCVE-2026-31830Highsigstore: sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digestCVE-2026-1776Mediumcamaleon_cms: Camaleon CMS vulnerable to Path Traversal through AWS S3 uploader implementationCVE-2026-0980Highrubyipmi: rubyipmi is vulnerable to OS Command Injection through malicious usernamesGHSA-WX95-C6CV-8532Mediumnokogiri: Nokogiri does not check the return value from xmlC14NExecuteCVE-2026-25500Mediumrack: Stored XSS in Rack::Directory via javascript: filenames rendered into anchor hrefCVE-2026-22860Highrack: Rack has a Directory Traversal via Rack:DirectoryGHSA-Q66H-M87M-J2Q6Lowbitcoinrb: Bitcoinrb Vulnerable to Command injection via RPC CVE-2026-25765Mediumfaraday: Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_urlGHSA-W67G-2H6V-VJGQHighphlex: Phlex XSS protection bypass via attribute splatting, dynamic tags, and href valuesCVE-2026-25758Highspree_api: Unauthenticated Spree Commerce users can access all guest addressesCVE-2026-25757Highspree_storefront: Unauthenticated Spree Commerce users can view completed guest orders by Order ID

Stop the waste.
Protect your environment with Kodem.