Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9hj4-r449-hfvc
  • RubyGems/json
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams 2 days ago
  • Fix available
GHSA-g65v-27r3-5p6m
  • RubyGems/guard-livereload
guard-livereload has a directory traversal vulnerability 31 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-mx5j-mp4f-g8jg
  • RubyGems/savon
Savon::Model evaluates WSDL operation names as Ruby source 31 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-xr9x-r78c-5hrm
  • RubyGems/activestorage
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing 30 Jul
  • Fix available
  • Severity - 9.5 (Critical)
GHSA-4mrv-5p47-p938
  • RubyGems/msgpack
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure 30 Jul
  • Fix available
  • Severity - 2.1 (Low)
GHSA-5p9g-j988-pcwv
  • RubyGems/mcp
MCP Ruby SDK: Ruby SSE Session Poisoning 30 Jul
  • Fix available
  • Severity - 8.3 (High)
GHSA-h669-8m4g-r2hc
  • RubyGems/mcp
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport 30 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-52jp-gj8w-j6xh
  • RubyGems/mcp
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood 30 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7683-3w9x-ch42
  • RubyGems/mcp
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) 30 Jul
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-rjr6-rcgv-9m7m
  • RubyGems/mcp
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection 30 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-pmwx-rm49-xv39
  • RubyGems/activerecord-tenanted
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal 29 Jul
  • Fix available
  • Severity - 2.3 (Low)
GHSA-2xmw-f8j8-wfxc
  • RubyGems/pagy
Pagy I18n locale option is not validated before being used in a file path 28 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-pp92-crg2-gfv9
  • RubyGems/oauth2
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host 28 Jul
  • Fix available
  • Severity - 8.6 (High)
GHSA-prq8-7wvh-44qh
  • RubyGems/oauth
OAuth: Cross-origin token-request redirects can expose signed request metadata 28 Jul
  • Fix available
  • Severity - 7.2 (High)
GHSA-j7fr-3v8c-3qc3
  • RubyGems/sqlite3
  • RubyGems/sqlite3-ruby
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks 28 Jul
  • Fix available
  • Severity - 2.0 (Low)
GHSA-28hh-pr2h-2w89
  • RubyGems/sqlite3
  • RubyGems/sqlite3-ruby
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity 28 Jul
  • Fix available
  • Severity - 2.0 (Low)