Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,144 advisories

Loading
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` High
CVE-2026-54904 was published for concurrent-ruby (RubyGems) Jun 19, 2026
pranjalithakur Credited to pranjalithakur and EchoTydes EchoTydes EchoTydes
katello: missing repository authorization in content_uploads exposes cross-product content existence Moderate
CVE-2026-12515 was published for katello (RubyGems) Jun 17, 2026
guard-livereload has a directory traversal vulnerability Moderate
CVE-2016-1000305 was published for guard-livereload (RubyGems) Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source High
CVE-2026-53510 was published for savon (RubyGems) Jul 31, 2026
connorshea Credited to connorshea
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type Low
GHSA-wjv4-x9w8-wm3h was published for nokogiri (RubyGems) Jun 19, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing Critical
CVE-2026-66066 was published for activestorage (RubyGems) Jul 30, 2026
0xacb Credited to 0xacb, Ry0taK, flavorjones, jeremy, byroot, ethiack-admin, s3np41k1r1t0, castilho101, and rafaelfranca Ry0taK Ry0taK
flavorjones flavorjones jeremy jeremy byroot byroot ethiack-admin ethiack-admin s3np41k1r1t0 s3np41k1r1t0 castilho101 castilho101 rafaelfranca rafaelfranca
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure Low
CVE-2026-54522 was published for msgpack (RubyGems) Jul 30, 2026
pranjalithakur Credited to pranjalithakur
MCP Ruby SDK: Ruby SSE Session Poisoning High
CVE-2026-67431 was published for mcp (RubyGems) Jul 30, 2026
srikanthramu Credited to srikanthramu
hewei-gikaku Credited to hewei-gikaku
hewei-gikaku Credited to hewei-gikaku
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) Moderate
CVE-2026-63119 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection Moderate
CVE-2026-63118 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot, dodge1218, and hewei-gikaku dodge1218 dodge1218
hewei-gikaku hewei-gikaku
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal Low
GHSA-pmwx-rm49-xv39 was published for activerecord-tenanted (RubyGems) Jul 29, 2026
tonghuaroot Credited to tonghuaroot
Pagy I18n locale option is not validated before being used in a file path Moderate
CVE-2026-54659 was published for pagy (RubyGems) Jul 28, 2026
7a6163 Credited to 7a6163
tonghuaroot Credited to tonghuaroot and pboling pboling pboling
OAuth: Cross-origin token-request redirects can expose signed request metadata High
CVE-2026-54605 was published for oauth (RubyGems) Jul 28, 2026
pboling Credited to pboling
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks Low
CVE-2026-54620 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity Low
CVE-2026-54619 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Ruby json: JSON generator heap buffer overflow when streaming to an IO Low
CVE-2026-54696 was published for json (RubyGems) Jul 23, 2026
susdrip Credited to susdrip
net-imap vulnerable to command Injection via unvalidated Symbol inputs Moderate
CVE-2026-42258 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
MoonFuji Credited to MoonFuji
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
websocket-driver-ruby: Denial of service via malformed Host header High
CVE-2026-61666 was published for websocket-driver (RubyGems) Jul 21, 2026
pranjalithakur Credited to pranjalithakur
ProTip! Advisories are also available from the GraphQL API