Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,135 advisories

Loading
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal Low
GHSA-pmwx-rm49-xv39 was published for activerecord-tenanted (RubyGems) Jul 29, 2026
tonghuaroot Credited to tonghuaroot
Pagy I18n locale option is not validated before being used in a file path Moderate
CVE-2026-54659 was published for pagy (RubyGems) Jul 28, 2026
7a6163 Credited to 7a6163
tonghuaroot Credited to tonghuaroot and pboling pboling pboling
OAuth: Cross-origin token-request redirects can expose signed request metadata High
CVE-2026-54605 was published for oauth (RubyGems) Jul 28, 2026
pboling Credited to pboling
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks Low
CVE-2026-54620 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity Low
CVE-2026-54619 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Ruby json: JSON generator heap buffer overflow when streaming to an IO Low
CVE-2026-54696 was published for json (RubyGems) Jul 23, 2026
susdrip Credited to susdrip
net-imap vulnerable to command Injection via unvalidated Symbol inputs Moderate
CVE-2026-42258 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
MoonFuji Credited to MoonFuji
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
websocket-driver-ruby: Denial of service via malformed Host header High
CVE-2026-61666 was published for websocket-driver (RubyGems) Jul 21, 2026
pranjalithakur Credited to pranjalithakur
Excon does not redact additional sensitive/risky headers when following redirects Moderate
CVE-2026-54171 was published for excon (RubyGems) Jul 10, 2026
SnailSploit Credited to SnailSploit, Lokeninfinitypoint, and Amayyas Lokeninfinitypoint Lokeninfinitypoint
Amayyas Amayyas
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references Low
GHSA-8whx-365g-h9vv was published for loofah (RubyGems) Jul 21, 2026
connorshea Credited to connorshea
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity Low
CVE-2026-54905 was published for concurrent-ruby (RubyGems) Jun 19, 2026
pranjalithakur Credited to pranjalithakur
katello: missing repository authorization in content_uploads exposes cross-product content existence Moderate
CVE-2026-12515 was published for katello (RubyGems) Jun 17, 2026
xIllunight Credited to xIllunight and Paul-Bob Paul-Bob Paul-Bob
decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds Moderate
CVE-2024-45594 was published for decidim-meetings (RubyGems) Nov 13, 2024
whotwagner Credited to whotwagner
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50276 was published for datadog (RubyGems) Jul 15, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context Moderate
CVE-2026-54497 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
ViewComponent: around_render HTML-Safety Bypass High
CVE-2026-54498 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
websocket-driver: Memory exhaustion in HTTP header parser Moderate
CVE-2026-54465 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Resource limit bypass via message compression Moderate
CVE-2026-54464 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Memory exhaustion via abuse of protocol length headers Moderate
CVE-2026-54463 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
ProTip! Advisories are also available from the GraphQL API