RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-59830Highrack: Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parametersCVE-2025-58767Lowrexml: REXML has DoS condition when parsing malformed XML fileCVE-2025-58067Mediumgoogle_sign_in: Google Sign-In for Rails allowed redirect to protocol-relative URICVE-2025-57821Mediumgoogle_sign_in: Google Sign-In for Rails allowed redirects to malformed URLsCVE-2011-10026Criticalspree: Spree Commerce is vulnerable to RCE through Search APICVE-2025-24293Criticalactivestorage: Active Storage allowed transformation methods that were potentially unsafeCVE-2025-55193Mediumactiverecord: Active Record logging vulnerable to ANSI escape injectionCVE-2011-10019Criticalspree: Spree has Remote Command Execution vulnerability in search functionalityCVE-2025-54887Criticaljwe: JWE is missing AES-GCM authentication tag validation in encrypted JWECVE-2025-54572Mediumruby-saml: Ruby SAML DOS vulnerability with large SAML responseGHSA-353F-X4GH-CQQ8Criticalnokogiri: Nokogiri patches vendored libxml2 to resolve multiple CVEsGHSA-29G5-M8V7-V564Mediummeasured: Measured is vulnerable to Path Traversal attacks during class initializationCVE-2025-24294Mediumresolv: resolv vulnerable to DoS via insufficient DNS domain name length validationCVE-2025-53623Criticaljob-iteration: Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator classCVE-2025-34075Mediumvagrant: HashiCorp Vagrant has code injection vulnerability through default synced foldersCVE-2025-6442Mediumwebrick: Ruby WEBrick read_headers method can lead to HTTP Request/Response SmugglingCVE-2025-28382Highopenc3-cosmos-tool-iframe: OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpointCVE-2025-28384Criticalopenc3-cosmos-tool-iframe: OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpointCVE-2025-49007Mediumrack: ReDoS Vulnerability in Rack::Multipart handle_mime_headCVE-2025-48069Mediumgithub.com/Shopify/ejson2env/v2: Insufficient input sanitization in ejson2env CVE-2025-46727Highrack: Rack has an Unbounded-Parameter DoS in Rack::QueryParserCVE-2025-46336Mediumrack-session: Rack session gets restored after deletionCVE-2025-32441Mediumrack: Rack session gets restored after deletionCVE-2025-46551Mediumrubygems:jruby-openssl: JRuby-OpenSSL has hostname verification disabled by defaultCVE-2025-43857Mediumnet-imap: net-imap rubygem vulnerable to possible DoS by memory exhaustion

Stop the waste.
Protect your environment with Kodem.