Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

531 advisories

Loading
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory Moderate
CVE-2026-34763 was published for rack (RubyGems) Apr 2, 2026
harukioya Credited to harukioya, ioquatix, and jeremyevans ioquatix ioquatix
jeremyevans jeremyevans
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing Moderate
CVE-2026-32762 was published for rack (RubyGems) Apr 2, 2026
th4s1s Credited to th4s1s, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values Moderate
CVE-2026-26962 was published for rack (RubyGems) Apr 2, 2026
wtn Credited to wtn, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass. Moderate
CVE-2026-26961 was published for rack (RubyGems) Apr 2, 2026
CodeByMoriarty Credited to CodeByMoriarty, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges Moderate
CVE-2026-34826 was published for rack (RubyGems) Apr 2, 2026
orenyomtov Credited to orenyomtov, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Rack:: Static header_rules bypass via URL-encoded paths Moderate
CVE-2026-34786 was published for rack (RubyGems) Apr 2, 2026
harukioya Credited to harukioya, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
iCalendar has ICS injection via unsanitized URI property values Moderate
CVE-2026-33635 was published for icalendar (RubyGems) Mar 24, 2026
WesR Credited to WesR
Rails Active Storage has possible glob injection in its DiskService Moderate
CVE-2026-33202 was published for activestorage (RubyGems) Mar 23, 2026
Rails Active Support has a possible DoS vulnerability in its number helpers Moderate
CVE-2026-33176 was published for activesupport (RubyGems) Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests Moderate
CVE-2026-33174 was published for activestorage (RubyGems) Mar 23, 2026
Pirikara Credited to Pirikara
Rails Active Storage has possible content type bypass via metadata in direct uploads Moderate
CVE-2026-33173 was published for activestorage (RubyGems) Mar 23, 2026
Rails Active Support has a possible XSS vulnerability in SafeBuffer#% Moderate
CVE-2026-33170 was published for activesupport (RubyGems) Mar 23, 2026
ch4n3-yoon Credited to ch4n3-yoon
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited Moderate
CVE-2026-33169 was published for activesupport (RubyGems) Mar 23, 2026
ch4n3-yoon Credited to ch4n3-yoon
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby Moderate
CVE-2026-33306 was published for bcrypt (RubyGems) Mar 19, 2026
Avo has a XSS vulnerability on `return_to` param Moderate
CVE-2026-33209 was published for avo (RubyGems) Mar 18, 2026
timwis Credited to timwis
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to Moderate
CVE-2026-32700 was published for devise (RubyGems) Mar 17, 2026
grantcox Credited to grantcox and albinowax albinowax albinowax
Katello: Denial of Service and potential information disclosure via SQL injection Moderate
CVE-2026-4324 was published for katello (RubyGems) Mar 17, 2026
Trix has a Stored XSS vulnerability through serialized attributes Moderate
CVE-2026-73426 was published for action_text-trix (RubyGems) Mar 12, 2026
Camaleon CMS vulnerable to Path Traversal through AWS S3 uploader implementation Moderate
CVE-2026-1776 was published for camaleon_cms (RubyGems) Mar 10, 2026
Nokogiri does not check the return value from xmlC14NExecute Moderate
GHSA-wx95-c6cv-8532 was published for nokogiri (RubyGems) Feb 18, 2026
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href Moderate
CVE-2026-25500 was published for rack (RubyGems) Feb 17, 2026
thesmartshadow Credited to thesmartshadow, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url Moderate
CVE-2026-25765 was published for faraday (RubyGems) Feb 9, 2026
theamanrawat Credited to theamanrawat and neo-ai-engineer neo-ai-engineer neo-ai-engineer
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper Moderate
CVE-2026-23885 was published for alchemy_cms (RubyGems) Jan 21, 2026
TheDeepOpc Credited to TheDeepOpc and tvdeyen tvdeyen tvdeyen
Active Job - Object injection security vulnerability Moderate
GHSA-mpwp-4h2m-765c was published for activejob (RubyGems) Jan 16, 2026
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification Moderate
CVE-2026-22588 was published for spree_api (RubyGems) Jan 8, 2026
ProTip! Advisories are also available from the GraphQL API