GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,272
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,521
Pub
12
RubyGems
1,007
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,007 advisories
Filter by severity
Rails Active Storage has possible glob injection in its DiskService
Moderate
CVE-2026-33202
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
CVE-2026-33195
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Support has a possible DoS vulnerability in its number helpers
Moderate
CVE-2026-33176
was published
for
activesupport
(RubyGems)
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Moderate
CVE-2026-33174
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Moderate
CVE-2026-33173
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
Moderate
CVE-2026-33170
was published
for
activesupport
(RubyGems)
Mar 23, 2026
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
Moderate
CVE-2026-33169
was published
for
activesupport
(RubyGems)
Mar 23, 2026
Rails has a possible XSS vulnerability in its Action View tag helpers
Low
CVE-2026-33168
was published
for
actionview
(RubyGems)
Mar 23, 2026
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
Low
CVE-2026-33167
was published
for
actionpack
(RubyGems)
Mar 23, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
Critical
CVE-2026-33286
was published
for
graphiti
(RubyGems)
Mar 20, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Moderate
CVE-2026-33306
was published
for
bcrypt
(RubyGems)
Mar 19, 2026
Ruby JSON has a format string injection vulnerability
High
CVE-2026-33210
was published
for
json
(RubyGems)
Mar 19, 2026
Avo has a XSS vulnerability on `return_to` param
Moderate
CVE-2026-33209
was published
for
avo
(RubyGems)
Mar 18, 2026
Improper detection of disallowed URIs by Loofah `allowed_uri?`
Low
GHSA-46fp-8f5p-pf2m
was published
for
loofah
(RubyGems)
Mar 18, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Moderate
CVE-2026-32700
was published
for
devise
(RubyGems)
Mar 17, 2026
Katello: Denial of Service and potential information disclosure via SQL injection
Moderate
CVE-2026-4324
was published
for
katello
(RubyGems)
Mar 17, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
GHSA-qmpg-8xg6-ph5q
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
Camaleon CMS vulnerable to Path Traversal through AWS S3 uploader implementation
Moderate
CVE-2026-1776
was published
for
camaleon_cms
(RubyGems)
Mar 10, 2026
rubyipmi is vulnerable to OS Command Injection through malicious usernames
High
CVE-2026-0980
was published
for
rubyipmi
(RubyGems)
Feb 27, 2026
Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-wx95-c6cv-8532
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
Moderate
CVE-2026-25500
was published
for
rack
(RubyGems)
Feb 17, 2026
Rack has a Directory Traversal via Rack:Directory
High
CVE-2026-22860
was published
for
rack
(RubyGems)
Feb 17, 2026
Bitcoinrb Vulnerable to Command injection via RPC
Low
GHSA-q66h-m87m-j2q6
was published
for
bitcoinrb
(RubyGems)
Feb 10, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
Moderate
CVE-2026-25765
was published
for
faraday
(RubyGems)
Feb 9, 2026
ProTip!
Advisories are also available from the
GraphQL API