Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,152 advisories

Loading
decidim-elections: Election question titles allow stored script execution Moderate
CVE-2026-44282 was published for decidim-elections (RubyGems) Sep 9, 2026
Cassandra Web - Remote File Read High
CVE-2020-36939 was published for cassandra-web (RubyGems) Jan 27, 2026
simi Credited to simi
Mail: Email address spoofing via malformed RFC 2047 encoded-words Moderate
CVE-2026-63435 was published for mail (RubyGems) Sep 2, 2026
mantas Credited to mantas and glefait glefait glefait
Nokogiri CSS selector tokenizer has regular expression backtracking High
CVE-2026-79770 was published for nokogiri (RubyGems) May 6, 2026
colby-swandale Credited to colby-swandale and flavorjones flavorjones flavorjones
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking High
GHSA-5jhf-fpp7-v2pv was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
Nokogiri XSLT transform has a memory leak Moderate
CVE-2026-79771 was published for nokogiri (RubyGems) May 6, 2026
Captainjack-kor Credited to Captainjack-kor and flavorjones flavorjones flavorjones
Duplicate Advisory: Nokogiri XSLT transform has a memory leak Moderate
GHSA-rh9x-7xjc-vwx2 was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
Nokogiri does not check the return value from xmlC14NExecute Moderate
CVE-2026-79772 was published for nokogiri (RubyGems) Feb 18, 2026
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute Moderate
GHSA-xqqh-3w52-q8p7 was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) Critical
CVE-2026-55107 was published for kobako (RubyGems) Aug 18, 2026
alhafoudh Credited to alhafoudh
websocket-driver: Memory exhaustion in HTTP header parser Moderate
CVE-2026-54465 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Resource limit bypass via message compression Moderate
CVE-2026-54464 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Memory exhaustion via abuse of protocol length headers Moderate
CVE-2026-54463 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
CVE-2026-73648 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
connorshea Credited to connorshea
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
CVE-2026-73490 was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
CVE-2026-73428 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) Low
CVE-2026-73427 was published for action_text-trix (RubyGems) Mar 29, 2026
Trix has a Stored XSS vulnerability through serialized attributes Moderate
CVE-2026-73426 was published for action_text-trix (RubyGems) Mar 12, 2026
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` High
CVE-2026-54904 was published for concurrent-ruby (RubyGems) Jun 19, 2026
pranjalithakur Credited to pranjalithakur and EchoTydes EchoTydes EchoTydes
katello: missing repository authorization in content_uploads exposes cross-product content existence Moderate
CVE-2026-12515 was published for katello (RubyGems) Jun 17, 2026
guard-livereload has a directory traversal vulnerability Moderate
CVE-2016-1000305 was published for guard-livereload (RubyGems) Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source High
CVE-2026-53510 was published for savon (RubyGems) Jul 31, 2026
connorshea Credited to connorshea
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type Low
GHSA-wjv4-x9w8-wm3h was published for nokogiri (RubyGems) Jun 19, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
ProTip! Advisories are also available from the GraphQL API