Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
428770
AlmaLinux
4000
Alpaquita
6787
Alpine
3859
Android
2912
BellSoft Hardened Containers
230
Bitnami
6076
Chainguard
27073
CRAN
11
crates.io
1804
Debian
49549
Echo
1837
GHC
3
GIT
72032
GitHub Actions
37
Go
4710
Hackage
24
Hex
39
Linux
21438
Mageia
5674
Maven
5937
MinimOS
3885
npm
69476
NuGet
1471
openEuler
5144
openSUSE
10216
OSS-Fuzz
3671
Packagist
4832
Pub
10
PyPI
16665
Red Hat
17168
Rocky Linux
2280
RubyGems
1792
SUSE
16818
SwiftURL
42
Ubuntu
47258
Wolfi
14010
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mr3q-g2mv-mr4q
RubyGems/sinatra
Sinatra is vulnerable to ReDoS through ETag header value generation
10 Oct
Fix available
Severity - 2.7 (Low)
GHSA-6xw4-3v39-52mm
RubyGems/rack
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
10 Oct
Fix available
Severity - 7.5 (High)
GHSA-r657-rxjc-j557
RubyGems/rack
Rack has a Possible Information Disclosure Vulnerability
10 Oct
Fix available
Severity - 5.8 (Medium)
GHSA-wpv5-97wm-hp9c
RubyGems/rack
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
07 Oct
Fix available
Severity - 7.5 (High)
GHSA-w9pc-fmgc-vxvw
RubyGems/rack
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
07 Oct
Fix available
Severity - 7.5 (High)
GHSA-p543-xpfm-54cp
RubyGems/rack
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
07 Oct
Fix available
Severity - 7.5 (High)
MAL-2025-47815
RubyGems/sqlcommenter_rails
Malicious code in sqlcommenter_rails (RubyGems)
26 Sep
No fix available
MAL-2025-47816
RubyGems/your-gem-name12
Malicious code in your-gem-name12 (RubyGems)
26 Sep
No fix available
GHSA-625h-95r8-8xpm
RubyGems/rack
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
25 Sep
Fix available
Severity - 7.5 (High)
GHSA-c2f4-jgmc-q2r5
RubyGems/rexml
REXML has DoS condition when parsing malformed XML file
17 Sep
Fix available
Severity - 1.2 (Low)
MAL-2025-46925
RubyGems/authzd-client
Malicious code in authzd-client (RubyGems)
01 Sep
No fix available
MAL-2025-46924
RubyGems/advisory_db_toolkit
Malicious code in advisory_db_toolkit (RubyGems)
01 Sep
No fix available
MAL-2025-46926
RubyGems/github_chatops_extensions
Malicious code in github_chatops_extensions (RubyGems)
01 Sep
No fix available
MAL-2025-46930
RubyGems/monolith-twirp-mailreplies-replies
Malicious code in monolith-twirp-mailreplies-replies (RubyGems)
01 Sep
No fix available
MAL-2025-46931
RubyGems/monolith-twirp-merge-queue-go-mergequeuemonolith
Malicious code in monolith-twirp-merge-queue-go-mergequeuemonolith (RubyGems)
01 Sep
No fix available
MAL-2025-46929
RubyGems/monolith-twirp-github-repositories
Malicious code in monolith-twirp-github-repositories (RubyGems)
01 Sep
No fix available
Load more...
RubyGems - OSV