Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.3
RubyGems

GHSA-xqqh-3w52-q8p7

Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute

MEDIUM 5.3
RubyGems

GHSA-rh9x-7xjc-vwx2

Duplicate Advisory: Nokogiri XSLT transform has a memory leak

MEDIUM 4.7
RubyGems

CVE-2026-73490

Loofah: SVG `href` attribute bypasses local-reference restriction

MEDIUM 6.1
RubyGems

CVE-2026-40295

Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler

MEDIUM 5.3
RubyGems

CVE-2026-34826

Rack's multipart byte range processing allows denial of service via excessive overlapping ranges

MEDIUM 5.3
RubyGems

CVE-2026-26961

Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.

MEDIUM 4.8
RubyGems

CVE-2026-26962

Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values

MEDIUM 5.9
RubyGems

CVE-2026-34830

Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect

MEDIUM 4.8
RubyGems

CVE-2026-32762

Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing

MEDIUM 5.3
RubyGems

CVE-2026-34786

Rack:: Static header_rules bypass via URL-encoded paths

MEDIUM 4.8
RubyGems

CVE-2026-34831

Rack has Content-Length mismatch in Rack::Files error responses

MEDIUM 4.6
RubyGems

CVE-2026-73426

Trix has a Stored XSS vulnerability through serialized attributes

MEDIUM 5.8
RubyGems

CVE-2025-61780

Rack has a Possible Information Disclosure Vulnerability

MEDIUM 4.2
RubyGems

CVE-2025-46336

Rack session gets restored after deletion

MEDIUM 4.0
RubyGems

CVE-2025-27220

CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement

MEDIUM 5.4
RubyGems

CVE-2024-45614

Puma's header normalization allows for client to clobber proxy set headers

MEDIUM 5.9
RubyGems

CVE-2024-43398

REXML denial of service vulnerability

MEDIUM 5.3
RubyGems

CVE-2026-63435

Mail: Email address spoofing via malformed RFC 2047 encoded-words

MEDIUM 6.5
RubyGems

CVE-2026-54171

Excon does not redact additional sensitive/risky headers when following redirects

MEDIUM 5.5
RubyGems

CVE-2026-54905

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

MEDIUM 5.3
RubyGems

CVE-2026-54500

Oj: intern.c form_attr (uninitialized stack read)

MEDIUM 5.3
RubyGems

CVE-2026-79771

Nokogiri XSLT transform has a memory leak

MEDIUM 5.9
RubyGems

CVE-2026-44837

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

MEDIUM 5.3
RubyGems

CVE-2026-42258

net-imap vulnerable to command Injection via unvalidated Symbol inputs

MEDIUM 6.5
RubyGems

CVE-2026-44836

view_component: Preview Route Can Dispatch Inherited Helper Methods

MEDIUM 4.8
RubyGems

CVE-2026-34835

Rack::Request accepts invalid Host characters, enabling host allowlist bypass

MEDIUM 5.3
RubyGems

CVE-2026-34763

Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory

MEDIUM 4.3
RubyGems

CVE-2026-42085

OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames

MEDIUM 6.5
RubyGems

CVE-2026-33658

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

MEDIUM 5.4
RubyGems

CVE-2026-25500

Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href

MEDIUM 5.3
RubyGems

CVE-2026-79772

Nokogiri does not check the return value from xmlC14NExecute

MEDIUM 5.8
RubyGems

CVE-2026-25765

Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

MEDIUM 5.3
RubyGems

CVE-2025-14762

AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue

MEDIUM 5.3
RubyGems

CVE-2025-24294

resolv vulnerable to DoS via insufficient DNS domain name length validation

MEDIUM 4.2
RubyGems

CVE-2025-32441

Rack session gets restored after deletion

MEDIUM 6.5
RubyGems

CVE-2025-25184

Possible Log Injection in Rack::CommonLogger

MEDIUM 6.5
RubyGems

CVE-2025-25186

Possible DoS by memory exhaustion in net-imap

MEDIUM 5.4
RubyGems

CVE-2024-21510

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

MEDIUM 5.3
RubyGems

CVE-2024-27090

Decidim vulnerable to data disclosure through the embed feature

MEDIUM 6.8
RubyGems

CVE-2024-39308

RailsAdmin Cross-site Scripting vulnerability in the list view

MEDIUM 5.4
RubyGems

CVE-2024-27095

Decidim cross-site scripting (XSS) in the admin panel

MEDIUM 4.3
RubyGems

CVE-2024-39908

REXML denial of service vulnerability

MEDIUM 6.1
RubyGems

CVE-2024-32464

ActionText ContentAttachment can Contain Unsanitized HTML

MEDIUM 5.4
RubyGems

CVE-2024-28103

Missing security headers in Action Pack on non-HTML responses

MEDIUM 5.3
RubyGems

CVE-2024-35176

REXML contains a denial of service vulnerability

MEDIUM 4.5
RubyGems

CVE-2024-27281

RDoc RCE vulnerability with .rdoc_options

MEDIUM 5.0
RubyGems

CVE-2024-0227

Devise-Two-Factor vulnerable to brute force attacks

MEDIUM 4.5
RubyGems

CVE-2023-47635

Possible CSRF attack at questionnaire templates preview

MEDIUM 5.4
RubyGems

CVE-2024-27285

YARD's default template vulnerable to Cross-site Scripting in generated frames.html

MEDIUM 5.3
RubyGems

CVE-2024-26144

Rails has possible Sensitive Session Information Leak in Active Storage

MEDIUM 5.3
RubyGems

CVE-2024-25126

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

MEDIUM 6.3
RubyGems

CVE-2023-50727

Resque vulnerable to reflected XSS in Queue Endpoint

MEDIUM 6.3
RubyGems

CVE-2023-50724

Resque vulnerable to Reflected Cross Site Scripting through pathnames

MEDIUM 5.3
RubyGems

CVE-2023-36617

URI gem has ReDoS vulnerability

MEDIUM 4.2
RubyGems

CVE-2023-34246

Doorkeeper Improper Authentication vulnerability

MEDIUM 5.7
RubyGems

CVE-2023-48220

Possibility to circumvent the invitation token expiry period

MEDIUM 6.5
RubyGems

CVE-2024-22411

Cross-site scripting (XSS) in Action messages on Avo

MEDIUM 5.8
RubyGems

CVE-2023-38697

protocol-http1 HTTP Request/Response Smuggling vulnerability

MEDIUM 5.5
RubyGems

CVE-2023-38037

Active Support Possibly Discloses Locally Encrypted Files

MEDIUM 6.1
RubyGems

CVE-2013-4170

Ember.js Potential XSS Exploit When Binding `tagName` to User-Supplied Data

Ready to move

Start Securing

Free, no credit card | First findings in minutes