Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,135 advisories

Loading
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal Low
GHSA-pmwx-rm49-xv39 was published for activerecord-tenanted (RubyGems) Jul 29, 2026
tonghuaroot Credited to tonghuaroot
Pagy I18n locale option is not validated before being used in a file path Moderate
CVE-2026-54659 was published for pagy (RubyGems) Jul 28, 2026
7a6163 Credited to 7a6163
tonghuaroot Credited to tonghuaroot and pboling pboling pboling
OAuth: Cross-origin token-request redirects can expose signed request metadata High
CVE-2026-54605 was published for oauth (RubyGems) Jul 28, 2026
pboling Credited to pboling
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks Low
CVE-2026-54620 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity Low
CVE-2026-54619 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Ruby json: JSON generator heap buffer overflow when streaming to an IO Low
CVE-2026-54696 was published for json (RubyGems) Jul 23, 2026
susdrip Credited to susdrip
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
MoonFuji Credited to MoonFuji
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
websocket-driver-ruby: Denial of service via malformed Host header High
CVE-2026-61666 was published for websocket-driver (RubyGems) Jul 21, 2026
pranjalithakur Credited to pranjalithakur
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references Low
GHSA-8whx-365g-h9vv was published for loofah (RubyGems) Jul 21, 2026
connorshea Credited to connorshea
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50276 was published for datadog (RubyGems) Jul 15, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context Moderate
CVE-2026-54497 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
ViewComponent: around_render HTML-Safety Bypass High
CVE-2026-54498 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
websocket-driver: Memory exhaustion in HTTP header parser Moderate
CVE-2026-54465 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Resource limit bypass via message compression Moderate
CVE-2026-54464 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Memory exhaustion via abuse of protocol length headers Moderate
CVE-2026-54463 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
Decidim: Push subscriptions can be abused for server-side requests Moderate
CVE-2026-45573 was published for decidim-core (RubyGems) Jul 13, 2026
Decidim: HTML content blocks allow stored script execution Moderate
CVE-2026-45572 was published for decidim-core (RubyGems) Jul 13, 2026
Decidim: CSV census record endpoints improper authorization Moderate
CVE-2026-45415 was published for decidim-verifications (RubyGems) Jul 13, 2026
Decidim: JWT-backed authentication can be replayed across organizations High
CVE-2026-45414 was published for decidim (RubyGems) Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links High
CVE-2026-45378 was published for decidim-verifications (RubyGems) Jul 13, 2026
andreslucena Credited to andreslucena
Decidim: Private exports can be downloaded through reusable links Moderate
CVE-2026-45377 was published for decidim-core (RubyGems) Jul 13, 2026
ProTip! Advisories are also available from the GraphQL API