Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7pwq-q9jf-539h
  • RubyGems/kobako
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) yesterday
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-9hj4-r449-hfvc
  • RubyGems/json
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams 07 Aug
  • Fix available
GHSA-g65v-27r3-5p6m
  • RubyGems/guard-livereload
guard-livereload has a directory traversal vulnerability 31 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-mx5j-mp4f-g8jg
  • RubyGems/savon
Savon::Model evaluates WSDL operation names as Ruby source 31 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-xr9x-r78c-5hrm
  • RubyGems/activestorage
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing 30 Jul
  • Fix available
  • Severity - 9.5 (Critical)
GHSA-4mrv-5p47-p938
  • RubyGems/msgpack
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure 30 Jul
  • Fix available
  • Severity - 2.1 (Low)
GHSA-5p9g-j988-pcwv
  • RubyGems/mcp
MCP Ruby SDK: Ruby SSE Session Poisoning 30 Jul
  • Fix available
  • Severity - 8.3 (High)
GHSA-h669-8m4g-r2hc
  • RubyGems/mcp
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport 30 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-52jp-gj8w-j6xh
  • RubyGems/mcp
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood 30 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7683-3w9x-ch42
  • RubyGems/mcp
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) 30 Jul
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-rjr6-rcgv-9m7m
  • RubyGems/mcp
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection 30 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-2xmw-f8j8-wfxc
  • RubyGems/pagy
Pagy I18n locale option is not validated before being used in a file path 28 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-j7fr-3v8c-3qc3
  • RubyGems/sqlite3
  • RubyGems/sqlite3-ruby
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks 28 Jul
  • Fix available
  • Severity - 2.0 (Low)
GHSA-28hh-pr2h-2w89
  • RubyGems/sqlite3
  • RubyGems/sqlite3-ruby
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity 28 Jul
  • Fix available
  • Severity - 2.0 (Low)
GHSA-53g2-mvcc-q9x3
  • RubyGems/action_text-trix
  • npm/trix
Trix: Stored XSS via HTMLParser attribute injection on paste 24 Jul
  • Fix available
  • Severity - 4.6 (Medium)
GHSA-x2f5-4prf-w687
  • RubyGems/json
Ruby json: JSON generator heap buffer overflow when streaming to an IO 23 Jul
  • Fix available
  • Severity - 3.7 (Low)