Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

534 advisories

Loading
Mail: Email address spoofing via malformed RFC 2047 encoded-words Moderate
CVE-2026-63435 was published for mail (RubyGems) Sep 2, 2026
mantas Credited to mantas and glefait glefait glefait
Nokogiri XSLT transform has a memory leak Moderate
CVE-2026-79771 was published for nokogiri (RubyGems) May 6, 2026
Captainjack-kor Credited to Captainjack-kor and flavorjones flavorjones flavorjones
Duplicate Advisory: Nokogiri XSLT transform has a memory leak Moderate
GHSA-rh9x-7xjc-vwx2 was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
Nokogiri does not check the return value from xmlC14NExecute Moderate
CVE-2026-79772 was published for nokogiri (RubyGems) Feb 18, 2026
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute Moderate
GHSA-xqqh-3w52-q8p7 was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
websocket-driver: Memory exhaustion in HTTP header parser Moderate
CVE-2026-54465 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Resource limit bypass via message compression Moderate
CVE-2026-54464 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Memory exhaustion via abuse of protocol length headers Moderate
CVE-2026-54463 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
CVE-2026-73648 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
CVE-2026-73490 was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
CVE-2026-73428 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Trix has a Stored XSS vulnerability through serialized attributes Moderate
CVE-2026-73426 was published for action_text-trix (RubyGems) Mar 12, 2026
katello: missing repository authorization in content_uploads exposes cross-product content existence Moderate
CVE-2026-12515 was published for katello (RubyGems) Jun 17, 2026
guard-livereload has a directory traversal vulnerability Moderate
CVE-2016-1000305 was published for guard-livereload (RubyGems) Jul 31, 2026
hewei-gikaku Credited to hewei-gikaku
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) Moderate
CVE-2026-63119 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection Moderate
CVE-2026-63118 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot, dodge1218, and hewei-gikaku dodge1218 dodge1218
hewei-gikaku hewei-gikaku
Pagy I18n locale option is not validated before being used in a file path Moderate
CVE-2026-54659 was published for pagy (RubyGems) Jul 28, 2026
7a6163 Credited to 7a6163
net-imap vulnerable to command Injection via unvalidated Symbol inputs Moderate
CVE-2026-42258 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
Excon does not redact additional sensitive/risky headers when following redirects Moderate
CVE-2026-54171 was published for excon (RubyGems) Jul 10, 2026
SnailSploit Credited to SnailSploit, Lokeninfinitypoint, and Amayyas Lokeninfinitypoint Lokeninfinitypoint
Amayyas Amayyas
decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds Moderate
CVE-2024-45594 was published for decidim-meetings (RubyGems) Nov 13, 2024
whotwagner Credited to whotwagner
ViewComponent: Reused Component Instances Retain Stale Render Context Moderate
CVE-2026-54497 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
Decidim: Push subscriptions can be abused for server-side requests Moderate
CVE-2026-45573 was published for decidim-core (RubyGems) Jul 13, 2026
Decidim: HTML content blocks allow stored script execution Moderate
CVE-2026-45572 was published for decidim-core (RubyGems) Jul 13, 2026
Decidim: CSV census record endpoints improper authorization Moderate
CVE-2026-45415 was published for decidim-verifications (RubyGems) Jul 13, 2026
ProTip! Advisories are also available from the GraphQL API