Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-53g2-mvcc-q9x3
  • RubyGems/action_text-trix
  • npm/trix
Trix: Stored XSS via HTMLParser attribute injection on paste 3 days ago
  • Fix available
  • Severity - 4.6 (Medium)
GHSA-x2f5-4prf-w687
  • RubyGems/json
Ruby json: JSON generator heap buffer overflow when streaming to an IO 4 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-cj75-f6xr-r4g7
  • RubyGems/rails-html-sanitizer
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations 6 days ago
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-5qhf-9phg-95m2
  • RubyGems/loofah
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons 6 days ago
  • Fix available
  • Severity - 2.3 (Low)
GHSA-9wjq-cp2p-hrgf
  • RubyGems/loofah
Loofah: SVG `href` attribute bypasses local-reference restriction 6 days ago
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-2x63-gw47-w4mm
  • RubyGems/websocket-driver
websocket-driver-ruby: Denial of service via malformed Host header 6 days ago
  • Fix available
  • Severity - 8.9 (High)
GHSA-8whx-365g-h9vv
  • RubyGems/loofah
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references 21 Jul
  • Fix available
  • Severity - 2.3 (Low)
MAL-2026-10914
  • RubyGems/my_shoaib_gem
Malicious code in my_shoaib_gem (RubyGems) 20 Jul
  • No fix available
MAL-2026-10913
  • RubyGems/ike-artifactory-ruby
Malicious code in ike-artifactory-ruby (RubyGems) 20 Jul
  • No fix available
GHSA-p5f6-rccc-jv98
  • RubyGems/datadog
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS 15 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-9h85-g7w3-rh49
  • RubyGems/view_component
ViewComponent: Reused Component Instances Retain Stale Render Context 15 Jul
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-97jw-64cj-jc58
  • RubyGems/view_component
ViewComponent: around_render HTML-Safety Bypass 15 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-8j3g-f24p-4mpw
  • RubyGems/websocket-driver
websocket-driver: Memory exhaustion in HTTP header parser 15 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-33ph-fccm-39pj
  • RubyGems/websocket-driver
websocket-driver: Resource limit bypass via message compression 15 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-ghhp-3qvg-889p
  • RubyGems/websocket-driver
websocket-driver: Memory exhaustion via abuse of protocol length headers 15 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-2g9c-vf8h-prxx
  • RubyGems/decidim-core
Decidim: Push subscriptions can be abused for server-side requests 13 Jul
  • Fix available
  • Severity - 6.4 (Medium)