GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,150 advisories
Filter by severity
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Moderate
CVE-2026-63435
was published
for
mail
(RubyGems)
Sep 2, 2026
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-xqqh-3w52-q8p7
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-5jhf-fpp7-v2pv
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
Moderate
GHSA-rh9x-7xjc-vwx2
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Critical
CVE-2026-55107
was published
for
kobako
(RubyGems)
Aug 18, 2026
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Low
CVE-2026-71847
was published
for
json
(RubyGems)
Aug 7, 2026
guard-livereload has a directory traversal vulnerability
Moderate
CVE-2016-1000305
was published
for
guard-livereload
(RubyGems)
Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source
High
CVE-2026-53510
was published
for
savon
(RubyGems)
Jul 31, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
CVE-2026-66066
was published
for
activestorage
(RubyGems)
Jul 30, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
CVE-2026-54522
was published
for
msgpack
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning
High
CVE-2026-67431
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
High
CVE-2026-67432
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
Moderate
CVE-2026-67430
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
Moderate
CVE-2026-63119
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
Moderate
CVE-2026-63118
was published
for
mcp
(RubyGems)
Jul 30, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
Pagy I18n locale option is not validated before being used in a file path
Moderate
CVE-2026-54659
was published
for
pagy
(RubyGems)
Jul 28, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
CVE-2026-73428
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Ruby json: JSON generator heap buffer overflow when streaming to an IO
Low
CVE-2026-54696
was published
for
json
(RubyGems)
Jul 23, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
CVE-2026-73648
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API