GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,013 advisories
Filter by severity
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Ruby LSP has arbitrary code execution through branch setting
High
CVE-2026-34060
was published
for
ruby-lsp
(RubyGems)
Mar 27, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
GHSA-2j22-pr5w-6gq8
was published
for
loofah
(RubyGems)
Mar 26, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
CVE-2026-33658
was published
for
activestorage
(RubyGems)
Mar 25, 2026
iCalendar has ICS injection via unsanitized URI property values
Moderate
CVE-2026-33635
was published
for
icalendar
(RubyGems)
Mar 24, 2026
Rails Active Storage has possible glob injection in its DiskService
Moderate
CVE-2026-33202
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
CVE-2026-33195
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Support has a possible DoS vulnerability in its number helpers
Moderate
CVE-2026-33176
was published
for
activesupport
(RubyGems)
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Moderate
CVE-2026-33174
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Moderate
CVE-2026-33173
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
Moderate
CVE-2026-33170
was published
for
activesupport
(RubyGems)
Mar 23, 2026
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
Moderate
CVE-2026-33169
was published
for
activesupport
(RubyGems)
Mar 23, 2026
Rails has a possible XSS vulnerability in its Action View tag helpers
Low
CVE-2026-33168
was published
for
actionview
(RubyGems)
Mar 23, 2026
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
Low
CVE-2026-33167
was published
for
actionpack
(RubyGems)
Mar 23, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
Critical
CVE-2026-33286
was published
for
graphiti
(RubyGems)
Mar 20, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Moderate
CVE-2026-33306
was published
for
bcrypt
(RubyGems)
Mar 19, 2026
Ruby JSON has a format string injection vulnerability
High
CVE-2026-33210
was published
for
json
(RubyGems)
Mar 19, 2026
Avo has a XSS vulnerability on `return_to` param
Moderate
CVE-2026-33209
was published
for
avo
(RubyGems)
Mar 18, 2026
Improper detection of disallowed URIs by Loofah `allowed_uri?`
Low
GHSA-46fp-8f5p-pf2m
was published
for
loofah
(RubyGems)
Mar 18, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Moderate
CVE-2026-32700
was published
for
devise
(RubyGems)
Mar 17, 2026
Katello: Denial of Service and potential information disclosure via SQL injection
Moderate
CVE-2026-4324
was published
for
katello
(RubyGems)
Mar 17, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
GHSA-qmpg-8xg6-ph5q
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
Camaleon CMS vulnerable to Path Traversal through AWS S3 uploader implementation
Moderate
CVE-2026-1776
was published
for
camaleon_cms
(RubyGems)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API