Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
GHSA-xqqh-3w52-q8p7
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
GHSA-rh9x-7xjc-vwx2
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
CVE-2026-73490
Loofah: SVG `href` attribute bypasses local-reference restriction
CVE-2026-40295
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
CVE-2026-34826
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
CVE-2026-26961
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
CVE-2026-26962
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
CVE-2026-34830
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
CVE-2026-32762
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
CVE-2026-34786
Rack:: Static header_rules bypass via URL-encoded paths
CVE-2026-34831
Rack has Content-Length mismatch in Rack::Files error responses
CVE-2026-73426
Trix has a Stored XSS vulnerability through serialized attributes
CVE-2025-61780
Rack has a Possible Information Disclosure Vulnerability
CVE-2025-46336
Rack session gets restored after deletion
CVE-2025-27220
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
CVE-2024-45614
Puma's header normalization allows for client to clobber proxy set headers
CVE-2024-43398
REXML denial of service vulnerability
CVE-2026-63435
Mail: Email address spoofing via malformed RFC 2047 encoded-words
CVE-2026-54171
Excon does not redact additional sensitive/risky headers when following redirects
CVE-2026-54905
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
CVE-2026-54500
Oj: intern.c form_attr (uninitialized stack read)
CVE-2026-79771
Nokogiri XSLT transform has a memory leak
CVE-2026-44837
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
CVE-2026-42258
net-imap vulnerable to command Injection via unvalidated Symbol inputs
CVE-2026-44836
view_component: Preview Route Can Dispatch Inherited Helper Methods
CVE-2026-34835
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
CVE-2026-34763
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
CVE-2026-42085
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
CVE-2026-33658
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
CVE-2026-25500
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
CVE-2026-79772
Nokogiri does not check the return value from xmlC14NExecute
CVE-2026-25765
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
CVE-2025-14762
AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue
CVE-2025-24294
resolv vulnerable to DoS via insufficient DNS domain name length validation
CVE-2025-32441
Rack session gets restored after deletion
CVE-2025-25184
Possible Log Injection in Rack::CommonLogger
CVE-2025-25186
Possible DoS by memory exhaustion in net-imap
CVE-2024-21510
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
CVE-2024-27090
Decidim vulnerable to data disclosure through the embed feature
CVE-2024-39308
RailsAdmin Cross-site Scripting vulnerability in the list view
CVE-2024-27095
Decidim cross-site scripting (XSS) in the admin panel
CVE-2024-39908
REXML denial of service vulnerability
CVE-2024-32464
ActionText ContentAttachment can Contain Unsanitized HTML
CVE-2024-28103
Missing security headers in Action Pack on non-HTML responses
CVE-2024-35176
REXML contains a denial of service vulnerability
CVE-2024-27281
RDoc RCE vulnerability with .rdoc_options
CVE-2024-0227
Devise-Two-Factor vulnerable to brute force attacks
CVE-2023-47635
Possible CSRF attack at questionnaire templates preview
CVE-2024-27285
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
CVE-2024-26144
Rails has possible Sensitive Session Information Leak in Active Storage
CVE-2024-25126
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
CVE-2023-50727
Resque vulnerable to reflected XSS in Queue Endpoint
CVE-2023-50724
Resque vulnerable to Reflected Cross Site Scripting through pathnames
CVE-2023-36617
URI gem has ReDoS vulnerability
CVE-2023-34246
Doorkeeper Improper Authentication vulnerability
CVE-2023-48220
Possibility to circumvent the invitation token expiry period
CVE-2024-22411
Cross-site scripting (XSS) in Action messages on Avo
CVE-2023-38697
protocol-http1 HTTP Request/Response Smuggling vulnerability
CVE-2023-38037
Active Support Possibly Discloses Locally Encrypted Files
CVE-2013-4170
Ember.js Potential XSS Exploit When Binding `tagName` to User-Supplied Data
Ready to move
Start Securing
Free, no credit card | First findings in minutes