Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-85396
rubyzip path traversal vulnerability
CVE-2026-77601
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
CVE-2026-94462
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
CVE-2026-57579
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
CVE-2026-70658
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
CVE-2026-47737
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVE-2026-42084
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
CVE-2026-34230
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVE-2026-41316
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
CVE-2026-34785
Rack::Static prefix matching can expose unintended files under the static root
CVE-2026-35611
Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-34829
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-59830
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
CVE-2025-54314
Withdrawn Advisory: Thor can construct an unsafe shell command from library input.
CVE-2025-46727
Rack has an Unbounded-Parameter DoS in Rack::QueryParser
CVE-2025-71406
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
CVE-2026-54592
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
GHSA-5jhf-fpp7-v2pv
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
CVE-2026-54603
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
CVE-2026-47736
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
CVE-2026-44025
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
CVE-2026-44160
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
CVE-2026-54904
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
CVE-2026-54297
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
CVE-2026-44161
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
CVE-2026-45363
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
CVE-2026-79770
Nokogiri CSS selector tokenizer has regular expression backtracking
CVE-2026-34827
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
CVE-2026-22860
Rack has a Directory Traversal via Rack:Directory
CVE-2025-68696
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
CVE-2025-61771
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
CVE-2025-61772
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
CVE-2025-61770
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
CVE-2025-61919
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
CVE-2024-49761
REXML ReDoS vulnerability
CVE-2024-47220
HTTP Request Smuggling in ruby webrick
CVE-2024-41946
REXML DoS vulnerability
CVE-2024-41123
REXML DoS vulnerability
CVE-2024-32469
Decidim cross-site scripting (XSS) in the pagination
CVE-2024-32970
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
CVE-2024-35231
rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter
CVE-2024-32463
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
CVE-2024-28121
StimulusReflex arbitrary method call
CVE-2024-28181
TurboBoost Commands vulnerable to arbitrary method invocation
CVE-2023-34089
Decidim Cross-site Scripting vulnerability in the processes filter
CVE-2023-28756
Ruby Time component ReDoS issue
GHSA-4553-hq82-8654
Duplicate Advisory: encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
CVE-2024-21632
Omniauth::MicrosoftGraph Account takeover (nOAuth)
CVE-2023-34103
avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields
CVE-2023-34102
avo possible unsafe reflection / partial DoS vulnerability
CVE-2024-22191
avo vulnerable to stored cross-site scripting (XSS) in key_value field
CVE-2024-28199
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
CVE-2023-4785
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVE-2023-36465
Decidim has broken access control in templates
CVE-2023-0669
Withdrawn: Fortra GoAnywhere MFT Deserialization of Untrusted Data vulnerability affects metasploit-framework
CVE-2023-28755
Ruby URI component ReDoS issue
CVE-2025-27788
Out-of-bounds Read in Ruby JSON Parser
CVE-2025-27610
Local File Inclusion in Rack::Static
CVE-2020-8184
Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names
Ready to move
Start Securing
Free, no credit card | First findings in minutes