RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-65017Highdecidim-core: Decidim's private data exports can lead to data leaksCVE-2026-1530Highfog-kubevirt: fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validationCVE-2026-1531Highforeman_kubevirt: foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly setCVE-2026-23885Mediumalchemy_cms: AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelperGHSA-MPWP-4H2M-765CMediumactivejob: Active Job - Object injection security vulnerabilityGHSA-5QW5-WF2Q-F538Highactiverecord-jdbc-adapter: ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL InjectionCVE-2025-68271Criticalopenc3: openc3-api Vulnerable to Unauthenticated Remote Code ExecutionCVE-2026-22589Highspree_core: Spree API has Unauthenticated IDOR - Guest AddressCVE-2026-22588Mediumspree_api: Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order ModificationGHSA-96QW-H329-V5RGHighshakapacker: Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundlesGHSA-G9JG-W8VM-G96VMediumtrix: Trix has a stored XSS vulnerability through its attachment attributeCVE-2025-61594Lowuri: URI Credential Leakage Bypass over CVE-2025-27221CVE-2025-68696Highhttparty: httparty Has Potential SSRF Vulnerability That Leads to API Key LeakageCVE-2025-14762Mediumaws-sdk-s3: AWS SDK for Ruby's S3 Encryption Client has a Key Commitment IssueCVE-2025-68113Mediumaltcha-lib: ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayCVE-2025-66568Criticalruby-saml: Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validationCVE-2025-66567Criticalruby-saml: Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)CVE-2025-12790Highmqtt: MQTT does not validate hostnamesCVE-2025-64501Highprosemirror_to_html: Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute valuesCVE-2025-61921Lowsinatra: Sinatra is vulnerable to ReDoS through ETag header value generationCVE-2025-61919Highrack: Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingCVE-2025-61780Mediumrack: Rack has a Possible Information Disclosure VulnerabilityCVE-2025-61772Highrack: Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)CVE-2025-61771Highrack: Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)CVE-2025-61770Highrack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

Stop the waste.
Protect your environment with Kodem.