GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
30 advisories
Filter by severity
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
Moderate
CVE-2026-34835
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack has Content-Length mismatch in Rack::Files error responses
Moderate
CVE-2026-34831
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
Moderate
CVE-2026-34830
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
High
CVE-2026-34829
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
Moderate
CVE-2026-34763
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
Moderate
CVE-2026-34230
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
Moderate
CVE-2026-32762
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
Moderate
CVE-2026-26962
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
Low
CVE-2026-26961
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
High
CVE-2026-34827
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
Moderate
CVE-2026-34826
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack:: Static header_rules bypass via URL-encoded paths
Moderate
CVE-2026-34786
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack::Static prefix matching can expose unintended files under the static root
High
CVE-2026-34785
was published
for
rack
(RubyGems)
Apr 2, 2026
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
Moderate
CVE-2026-25500
was published
for
rack
(RubyGems)
Feb 17, 2026
Rack has a Directory Traversal via Rack:Directory
High
CVE-2026-22860
was published
for
rack
(RubyGems)
Feb 17, 2026
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
High
CVE-2025-61919
was published
for
rack
(RubyGems)
Oct 10, 2025
Rack has a Possible Information Disclosure Vulnerability
Moderate
CVE-2025-61780
was published
for
rack
(RubyGems)
Oct 10, 2025
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
High
CVE-2025-61772
was published
for
rack
(RubyGems)
Oct 7, 2025
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
High
CVE-2025-61771
was published
for
rack
(RubyGems)
Oct 7, 2025
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
High
CVE-2025-61770
was published
for
rack
(RubyGems)
Oct 7, 2025
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
High
CVE-2025-59830
was published
for
rack
(RubyGems)
Sep 25, 2025
Rack has an Unbounded-Parameter DoS in Rack::QueryParser
High
CVE-2025-46727
was published
for
rack
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-46336
was published
for
rack-session
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-32441
was published
for
rack
(RubyGems)
May 8, 2025
Local File Inclusion in Rack::Static
High
CVE-2025-27610
was published
for
rack
(RubyGems)
Mar 10, 2025
ProTip!
Advisories are also available from the
GraphQL API