rubygems

activesupport

View on rubygems registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether activesupport is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
RubyGems

CVE-2026-33169

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

UNKNOWN
RubyGems

CVE-2026-33170

Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

UNKNOWN
RubyGems

CVE-2026-33176

Rails Active Support has a possible DoS vulnerability in its number helpers

MEDIUM 5.5
RubyGems

CVE-2023-38037

Active Support Possibly Discloses Locally Encrypted Files

UNKNOWN
RubyGems

CVE-2015-3226

activesupport Cross-site Scripting vulnerability

CRITICAL 9.8
RubyGems

CVE-2020-8165

ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore

UNKNOWN
RubyGems

CVE-2009-3009

Cross site scripting that affects rails

UNKNOWN
RubyGems

CVE-2015-3227

activesupport vulnerable to Denial of Service via large XML document depth

UNKNOWN
RubyGems

CVE-2023-22796

ReDoS based DoS vulnerability in Active Support's underscore

UNKNOWN
RubyGems

CVE-2012-3464

activesupport Cross-site Scripting vulnerability

MEDIUM 5.3
RubyGems

CVE-2023-28120

Possible XSS Security Vulnerability in SafeBuffer#bytesplice

UNKNOWN
RubyGems

CVE-2011-2197

rails Cross-site Scripting vulnerability

UNKNOWN
RubyGems

CVE-2013-1856

activesupport Improper Input Validation vulnerability

UNKNOWN
RubyGems

GHSA-35c4-f3rq-f9g3

Moderate severity vulnerability that affects activesupport

UNKNOWN
RubyGems

CVE-2012-1098

activesupport Cross-site Scripting vulnerability

UNKNOWN
RubyGems

CVE-2013-0333

activesupport in Rails vulnerable to incorrect data conversion

UNKNOWN
RubyGems

CVE-2011-2932

activesupport Cross-site Scripting vulnerability

UNKNOWN
RubyGems

CVE-2009-3086

actionpack and activesupport vulnerable to information leaks

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes