Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
720025
AlmaLinux
5111
Alpaquita
11170
Alpine
4297
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
521
Bitnami
8150
Chainguard
7239
CleanStart
1519
CRAN
14
crates.io
2492
Debian
58818
Echo
5713
GHC
3
GIT
81705
GitHub Actions
54
Go
7881
Hackage
32
Hex
154
Julia
979
Linux
15361
Mageia
6003
Maven
6605
MinimOS
76172
npm
221013
NuGet
1756
opam
18
openEuler
7054
openSUSE
13144
OSS-Fuzz
3942
Packagist
6570
Pub
11
PyPI
20336
Red Hat
20824
Rocky Linux
3520
Root
16424
RubyGems
2007
SUSE
20972
SwiftURL
58
TuxCare
5651
Ubuntu
56527
VSCode
20
Wolfi
4766
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-pxcc-8665-phx8
RubyGems/yard
YARD static cache reads raw traversal paths before router sanitization
yesterday
Fix available
Severity - 5.3 (Medium)
GHSA-2jc5-xhx8-qj6h
RubyGems/fluent-plugin-opentelemetry
fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in
`
in_opentelemetry
`
yesterday
Fix available
Severity - 5.3 (Medium)
GHSA-xv9w-7v6q-hpjh
RubyGems/fluent-plugin-s3
fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in
`
in_s3
`
yesterday
Fix available
Severity - 2.7 (Low)
GHSA-72f5-rr8c-r6gr
RubyGems/fluentd
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in
`
out_http
`
yesterday
Fix available
Severity - 7.2 (High)
GHSA-j9cw-hwqf-85w7
RubyGems/fluentd
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in
`
in_http
`
and
`
in_forward
`
yesterday
Fix available
Severity - 7.5 (High)
GHSA-pr7j-96cj-549h
RubyGems/fluentd
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
yesterday
Fix available
Severity - 7.5 (High)
GHSA-44hj-4m45-frj3
RubyGems/fluentd
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in
`
${tag}
`
Placeholder
yesterday
Fix available
Severity - 9.8 (Critical)
GHSA-6wx8-w4f5-wwcr
RubyGems/concurrent-ruby
Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
19 Jun
Fix available
Severity - 2.1 (Low)
GHSA-wv3x-4vxv-whpp
RubyGems/concurrent-ruby
Concurrent Ruby:
`
ReentrantReadWriteLock
`
read-count overflow grants a write lock without exclusivity
19 Jun
Fix available
Severity - 2.0 (Low)
GHSA-h8w8-99g7-qmvj
RubyGems/concurrent-ruby
Concurrent Ruby :
`
AtomicReference#update
`
livelocks when the stored value is
`
Float::NAN
`
19 Jun
Fix available
Severity - 8.2 (High)
GHSA-475m-ph3x-64gp
RubyGems/oj
Oj: Integer Overflow in Oj.load 2GB String Handling
19 Jun
Fix available
Severity - 8.7 (High)
GHSA-m578-w5vf-rfcm
RubyGems/oj
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
19 Jun
Fix available
Severity - 8.7 (High)
GHSA-vwm4-62gf-x745
RubyGems/oj
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
19 Jun
Fix available
Severity - 8.7 (High)
GHSA-9cv6-qcjw-4grx
RubyGems/oj
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
19 Jun
Fix available
Severity - 8.7 (High)
GHSA-q2gm-54r6-8fwm
RubyGems/oj
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
19 Jun
Fix available
Severity - 8.7 (High)
GHSA-9ppp-w3g4-fh4q
RubyGems/oj
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
19 Jun
Fix available
Severity - 8.7 (High)
Load more...
RubyGems - OSV