RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-5W6V-399V-W3CCLownokogiri: Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415CVE-2024-39311Lowpublify_core: Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User InteractionCVE-2025-30221Mediumpitchfork: Pitchfork HTTP Request/Response Splitting vulnerabilityGHSA-MRXW-MXHJ-P664Highnokogiri: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEsCVE-2025-2304Criticalcamaleon_cms: Camaleon CMS Vulnerable to Privilege Escalation through a Mass AssignmentCVE-2025-25292Criticalruby-saml: Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)CVE-2025-25291Criticalruby-saml: Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)CVE-2025-25293Highruby-saml: Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responsesGHSA-HW46-3HMR-X9XVCriticalomniauth-saml: omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issueCVE-2025-27407Criticalgraphql: graphql allows remote code execution when loading a crafted GraphQL schemaCVE-2025-27788Highjson: Out-of-bounds Read in Ruby JSON Parser CVE-2025-27610Highrack: Local File Inclusion in Rack::StaticCVE-2025-27111Mediumrack: Escape Sequence Injection vulnerability in Rack lead to Possible Log InjectionCVE-2025-27221Lowuri: URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+CVE-2025-27220Mediumcgi: CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElementCVE-2025-27219Mediumcgi: CGI has Denial of Service (DoS) potential in Cookie.parseCVE-2025-27590Criticaloxidized-web: Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user accountCVE-2025-26803Mediumpassenger: Phusion Passenger denial of service GHSA-VVFQ-8HWR-QM4MLownokogiri: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171CVE-2025-25184Mediumrack: Possible Log Injection in Rack::CommonLoggerCVE-2025-25186Mediumnet-imap: Possible DoS by memory exhaustion in net-imapCVE-2024-56733Mediumpwpush: Password Pusher Allows Session Token Interception Leading to Potential HijackingCVE-2024-54133Lowactionpack: Possible Content Security Policy bypass in Action DispatchCVE-2024-53989Lowrails-html-sanitizer: rails-html-sanitizer has XSS vulnerability with certain configurationsCVE-2024-53987Lowrails-html-sanitizer: rails-html-sanitizer has XSS vulnerability with certain configurations

Stop the waste.
Protect your environment with Kodem.