Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 7.5
RubyGems

CVE-2026-85396

rubyzip path traversal vulnerability

HIGH 8.8
RubyGems

CVE-2026-77601

OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting

HIGH 7.1
RubyGems

CVE-2026-94462

Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)

HIGH 7.5
RubyGems

CVE-2026-57579

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

HIGH 7.4
RubyGems

CVE-2026-70658

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

HIGH 7.5
RubyGems

CVE-2026-47737

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

HIGH 8.1
RubyGems

CVE-2026-42084

OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence

HIGH 7.5
RubyGems

CVE-2026-34230

Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

HIGH 8.1
RubyGems

CVE-2026-41316

ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

HIGH 7.5
RubyGems

CVE-2026-34785

Rack::Static prefix matching can expose unintended files under the static root

HIGH 7.5
RubyGems

CVE-2026-35611

Addressable has a Regular Expression Denial of Service in Addressable templates

HIGH 7.5
RubyGems

CVE-2026-34829

Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads

HIGH 7.5
RubyGems

CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221

HIGH 7.5
RubyGems

CVE-2025-59830

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

HIGH 7.8
RubyGems

CVE-2025-54314

Withdrawn Advisory: Thor can construct an unsafe shell command from library input.

HIGH 7.5
RubyGems

CVE-2025-46727

Rack has an Unbounded-Parameter DoS in Rack::QueryParser

HIGH 7.8
RubyGems

CVE-2025-71406

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

HIGH 7.5
RubyGems

CVE-2026-54592

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

HIGH 7.5
RubyGems

GHSA-5jhf-fpp7-v2pv

Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking

HIGH 8.6
RubyGems

CVE-2026-54603

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

HIGH 7.5
RubyGems

CVE-2026-47736

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

HIGH 7.5
RubyGems

CVE-2026-44025

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

HIGH 7.5
RubyGems

CVE-2026-44160

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

HIGH 7.5
RubyGems

CVE-2026-54904

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

HIGH 7.5
RubyGems

CVE-2026-54297

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

HIGH 7.2
RubyGems

CVE-2026-44161

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

HIGH 7.4
RubyGems

CVE-2026-45363

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

HIGH 7.5
RubyGems

CVE-2026-79770

Nokogiri CSS selector tokenizer has regular expression backtracking

HIGH 7.5
RubyGems

CVE-2026-34827

Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters

HIGH 7.5
RubyGems

CVE-2026-22860

Rack has a Directory Traversal via Rack:Directory

HIGH 8.2
RubyGems

CVE-2025-68696

httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage

HIGH 7.5
RubyGems

CVE-2025-61771

Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)

HIGH 7.5
RubyGems

CVE-2025-61772

Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)

HIGH 7.5
RubyGems

CVE-2025-61770

Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

HIGH 7.5
RubyGems

CVE-2025-61919

Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing

HIGH 7.5
RubyGems

CVE-2024-49761

REXML ReDoS vulnerability

HIGH 7.5
RubyGems

CVE-2024-47220

HTTP Request Smuggling in ruby webrick

HIGH 7.5
RubyGems

CVE-2024-41946

REXML DoS vulnerability

HIGH 7.5
RubyGems

CVE-2024-41123

REXML DoS vulnerability

HIGH 7.1
RubyGems

CVE-2024-32469

Decidim cross-site scripting (XSS) in the pagination

HIGH 7.1
RubyGems

CVE-2024-32970

Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values

HIGH 8.6
RubyGems

CVE-2024-35231

rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter

HIGH 7.1
RubyGems

CVE-2024-32463

Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags

HIGH 8.8
RubyGems

CVE-2024-28121

StimulusReflex arbitrary method call

HIGH 8.1
RubyGems

CVE-2024-28181

TurboBoost Commands vulnerable to arbitrary method invocation

HIGH 8.1
RubyGems

CVE-2023-34089

Decidim Cross-site Scripting vulnerability in the processes filter

HIGH 7.5
RubyGems

CVE-2023-28756

Ruby Time component ReDoS issue

HIGH 7.5
RubyGems

GHSA-4553-hq82-8654

Duplicate Advisory: encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

HIGH 8.6
RubyGems

CVE-2024-21632

Omniauth::MicrosoftGraph Account takeover (nOAuth)

HIGH 7.3
RubyGems

CVE-2023-34103

avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields

HIGH 8.3
RubyGems

CVE-2023-34102

avo possible unsafe reflection / partial DoS vulnerability

HIGH 7.3
RubyGems

CVE-2024-22191

avo vulnerable to stored cross-site scripting (XSS) in key_value field

HIGH 7.1
RubyGems

CVE-2024-28199

Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex

HIGH 7.5
RubyGems

CVE-2023-4785

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

HIGH 7.1
RubyGems

CVE-2023-36465

Decidim has broken access control in templates

HIGH 7.2
RubyGems KEV

CVE-2023-0669

Withdrawn: Fortra GoAnywhere MFT Deserialization of Untrusted Data vulnerability affects metasploit-framework

HIGH 7.5
RubyGems

CVE-2023-28755

Ruby URI component ReDoS issue

HIGH 7.5
RubyGems

CVE-2025-27788

Out-of-bounds Read in Ruby JSON Parser

HIGH 7.5
RubyGems

CVE-2025-27610

Local File Inclusion in Rack::Static

HIGH 7.5
RubyGems

CVE-2020-8184

Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names

Ready to move

Start Securing

Free, no credit card | First findings in minutes