Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
CVE-2026-73648 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
CVE-2026-73490 was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Nokogiri XSLT transform has a memory leak Moderate
CVE-2026-79771 was published for nokogiri (RubyGems) May 6, 2026
Captainjack-kor Credited to Captainjack-kor and flavorjones flavorjones flavorjones
Bootstrap Vulnerable to Cross-Site Scripting Moderate
CVE-2019-8331 was published for Bootstrap.Less (RubyGems) Feb 22, 2019
flavorjones Credited to flavorjones and jasnow jasnow jasnow
ProTip! Advisories are also available from the GraphQL API