Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-85396
rubyzip path traversal vulnerability
CVE-2026-77602
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
CVE-2026-77601
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
CVE-2026-94462
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
CVE-2026-57579
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
CVE-2026-70658
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
GHSA-xqqh-3w52-q8p7
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
GHSA-rh9x-7xjc-vwx2
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
CVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
CVE-2026-66066
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
CVE-2026-54696
Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-73648
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
CVE-2026-73490
Loofah: SVG `href` attribute bypasses local-reference restriction
CVE-2026-73491
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
CVE-2026-73492
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
CVE-2026-54522
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
CVE-2026-44162
fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`
CVE-2026-57438
Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-54898
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
CVE-2026-57437
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-57435
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2026-54902
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-54897
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
CVE-2026-47241
Net::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-47240
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-57235
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-44024
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVE-2026-54903
Oj: Integer Overflow in Oj.load 2GB String Handling
CVE-2026-47242
Net::IMAP: Command Injection via ID command argument
CVE-2026-54896
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
CVE-2026-47737
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVE-2026-54899
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-42245
net-imap has quadratic complexity when reading response literals
CVE-2026-40295
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
CVE-2026-42257
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
CVE-2026-42256
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-33637
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
CVE-2026-34826
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
CVE-2026-42084
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
CVE-2026-26961
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
CVE-2026-26962
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
CVE-2026-34230
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVE-2026-34830
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
CVE-2026-32762
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
CVE-2026-41316
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
CVE-2026-34786
Rack:: Static header_rules bypass via URL-encoded paths
CVE-2026-34831
Rack has Content-Length mismatch in Rack::Files error responses
CVE-2026-34785
Rack::Static prefix matching can expose unintended files under the static root
CVE-2026-35611
Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-34829
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVE-2026-73426
Trix has a Stored XSS vulnerability through serialized attributes
CVE-2026-33195
Rails Active Storage has possible Path Traversal in DiskService
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-61780
Rack has a Possible Information Disclosure Vulnerability
CVE-2025-59830
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
CVE-2025-54314
Withdrawn Advisory: Thor can construct an unsafe shell command from library input.
CVE-2025-6490
sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow
CVE-2025-6494
sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow
CVE-2025-46727
Rack has an Unbounded-Parameter DoS in Rack::QueryParser
Ready to move
Start Securing
Free, no credit card | First findings in minutes