GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
356 advisories
Filter by severity
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
High
CVE-2026-45363
was published
for
jwt
(RubyGems)
May 18, 2026
katalyst-koi: Session cookies can be replayed after user logout
High
CVE-2026-44511
was published
for
katalyst-koi
(RubyGems)
May 7, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
High
CVE-2026-40069
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
High
CVE-2026-40070
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
Addressable has a Regular Expression Denial of Service in Addressable templates
High
CVE-2026-35611
was published
for
addressable
(RubyGems)
Apr 8, 2026
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
High
CVE-2026-34829
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
High
CVE-2026-34827
was published
for
rack
(RubyGems)
Apr 2, 2026
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
High
CVE-2026-34230
was published
for
rack
(RubyGems)
Apr 2, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
CVE-2026-33195
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Rack::Static prefix matching can expose unintended files under the static root
High
CVE-2026-34785
was published
for
rack
(RubyGems)
Apr 2, 2026
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
High
CVE-2026-42205
was published
for
avo
(RubyGems)
Apr 24, 2026
Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-c4rq-3m3g-8wgx
was published
for
nokogiri
(RubyGems)
May 6, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
CVE-2026-42084
was published
for
openc3
(RubyGems)
Apr 22, 2026
Decidim's comments API allows access to all commentable resources
High
CVE-2026-40870
was published
for
decidim-api
(RubyGems)
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
High
CVE-2026-40869
was published
for
decidim-core
(RubyGems)
Apr 14, 2026
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
High
CVE-2026-41146
was published
for
iodine
(RubyGems)
Apr 14, 2026
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
High
CVE-2026-41316
was published
for
erb
(RubyGems)
Apr 24, 2026
Regular Expression Denial of Service in Addressable templates
High
CVE-2021-32740
was published
for
addressable
(RubyGems)
Jul 12, 2021
Ruby LSP has arbitrary code execution through branch setting
High
CVE-2026-34060
was published
for
ruby-lsp
(RubyGems)
Mar 27, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
rubyipmi is vulnerable to OS Command Injection through malicious usernames
High
CVE-2026-0980
was published
for
rubyipmi
(RubyGems)
Feb 27, 2026
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
High
CVE-2026-1531
was published
for
foreman_kubevirt
(RubyGems)
Feb 2, 2026
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
High
CVE-2026-1530
was published
for
fog-kubevirt
(RubyGems)
Feb 2, 2026
Ruby JSON has a format string injection vulnerability
High
CVE-2026-33210
was published
for
json
(RubyGems)
Mar 19, 2026
ProTip!
Advisories are also available from the
GraphQL API