6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether devise is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.1
CVE-2026-40295
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
MEDIUM 5.3
CVE-2026-32700
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
HIGH 7.5
CVE-2015-8314
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
UNKNOWN
CVE-2013-0233
Devise does not properly perform type conversion when performing database queries
UNKNOWN
CVE-2019-5421
devise Time-of-check Time-of-use Race Condition vulnerability
MEDIUM 5.3
CVE-2019-16109
Authentication Bypass in Devise
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes