GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,842
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
390 advisories
Filter by severity
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
High
CVE-2026-77601
was published
for
openc3
(RubyGems)
Sep 23, 2026
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
High
CVE-2026-94462
was published
for
spree_api
(RubyGems)
Sep 22, 2026
MPXJ: XXE Vulnerability in MerlinReader
High
CVE-2026-61570
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
Cassandra Web - Remote File Read
High
CVE-2020-36939
was published
for
cassandra-web
(RubyGems)
Jan 27, 2026
Nokogiri CSS selector tokenizer has regular expression backtracking
High
CVE-2026-79770
was published
for
nokogiri
(RubyGems)
May 6, 2026
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-5jhf-fpp7-v2pv
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
High
CVE-2026-54904
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
Savon::Model evaluates WSDL operation names as Ruby source
High
CVE-2026-53510
was published
for
savon
(RubyGems)
Jul 31, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning
High
CVE-2026-67431
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
High
CVE-2026-67432
was published
for
mcp
(RubyGems)
Jul 30, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50276
was published
for
datadog
(RubyGems)
Jul 15, 2026
ViewComponent: around_render HTML-Safety Bypass
High
CVE-2026-54498
was published
for
view_component
(RubyGems)
Jul 15, 2026
Decidim: JWT-backed authentication can be replayed across organizations
High
CVE-2026-45414
was published
for
decidim
(RubyGems)
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
High
CVE-2026-45378
was published
for
decidim-verifications
(RubyGems)
Jul 13, 2026
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
High
CVE-2026-53727
was published
for
css_parser
(RubyGems)
Jul 9, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
High
GHSA-mjgf-xj26-9qf9
was published
for
pay
(RubyGems)
Jul 1, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
High
CVE-2026-54297
was published
for
faraday
(RubyGems)
Jun 19, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
High
CVE-2026-44161
was published
for
fluentd
(RubyGems)
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
High
CVE-2026-44160
was published
for
fluentd
(RubyGems)
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
High
CVE-2026-44025
was published
for
fluentd
(RubyGems)
Jun 26, 2026
Oj: Integer Overflow in Oj.load 2GB String Handling
High
CVE-2026-54903
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
High
CVE-2026-54902
was published
for
oj
(RubyGems)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API