GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
357 advisories
Filter by severity
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
High
CVE-2026-41316
was published
for
erb
(RubyGems)
Apr 24, 2026
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability
High
CVE-2019-18197
was published
for
nokogiri
(RubyGems)
May 24, 2022
libxslt Type Confusion vulnerability that affects Nokogiri
High
CVE-2019-13118
was published
for
nokogiri
(RubyGems)
May 24, 2022
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
High
CVE-2026-47737
was published
for
puma
(RubyGems)
Jun 9, 2026
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
High
CVE-2026-47736
was published
for
puma
(RubyGems)
Jun 8, 2026
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
High
CVE-2026-42205
was published
for
avo
(RubyGems)
Apr 24, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
CVE-2026-41146
was published
for
iodine
(RubyGems)
Apr 14, 2026
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
High
CVE-2026-45363
was published
for
jwt
(RubyGems)
May 18, 2026
Decidim's comments API allows access to all commentable resources
High
CVE-2026-40870
was published
for
decidim-api
(RubyGems)
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
High
CVE-2026-40869
was published
for
decidim-core
(RubyGems)
Apr 14, 2026
katalyst-koi: Session cookies can be replayed after user logout
High
CVE-2026-44511
was published
for
katalyst-koi
(RubyGems)
May 7, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
CVE-2026-42084
was published
for
openc3
(RubyGems)
Apr 22, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
High
CVE-2026-40069
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
High
CVE-2026-40070
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
Addressable has a Regular Expression Denial of Service in Addressable templates
High
CVE-2026-35611
was published
for
addressable
(RubyGems)
Apr 8, 2026
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
High
CVE-2026-34829
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
High
CVE-2026-34827
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
High
CVE-2026-34230
was published
for
rack
(RubyGems)
Apr 2, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
CVE-2026-33195
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rack::Static prefix matching can expose unintended files under the static root
High
CVE-2026-34785
was published
for
rack
(RubyGems)
Apr 2, 2026
Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-c4rq-3m3g-8wgx
was published
for
nokogiri
(RubyGems)
May 6, 2026
Regular Expression Denial of Service in Addressable templates
High
CVE-2021-32740
was published
for
addressable
(RubyGems)
Jul 12, 2021
Ruby LSP has arbitrary code execution through branch setting
High
CVE-2026-34060
was published
for
ruby-lsp
(RubyGems)
Mar 27, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API