<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ruby (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ruby.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ruby-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ruby (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46727 – An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46727</guid>
    <pubDate>Fri, 22 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46727</strong></p>
  <p>An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-bas…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42258 – Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42258</guid>
    <pubDate>Sat, 09 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42258</strong></p>
  <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42257 – Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42257</guid>
    <pubDate>Sat, 09 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42257</strong></p>
  <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP comm…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42246 – Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42246</guid>
    <pubDate>Sat, 09 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42246</strong></p>
  <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42245 – Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42245</guid>
    <pubDate>Sat, 09 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42245</strong></p>
  <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41493 – YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41493</guid>
    <pubDate>Fri, 08 May 2026 14:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41493</strong></p>
  <p>YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42088 – OpenC3 COSMOS provides the functionality needed to send commands to and receive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42088</guid>
    <pubDate>Mon, 04 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42088</strong></p>
  <p>OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API perm…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41316 – ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41316</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41316</strong></p>
  <p>ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27820 – zlib is a Ruby interface for the zlib compression/decompression library. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27820</guid>
    <pubDate>Thu, 16 Apr 2026 18:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27820</strong></p>
  <p>zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40070 – BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40070</guid>
    <pubDate>Thu, 09 Apr 2026 18:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40070</strong></p>
  <p>BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier's signature over the certificate contents. In acquisition_protocol: 'direct', the caller supplies all certificate fields (including signature:) and the record is written to storage verbatim. In acquis…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40069 – BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40069</guid>
    <pubDate>Thu, 09 Apr 2026 18:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40069</strong></p>
  <p>BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus are silently treated as successful broadcasts. Applications that gate actions on broadcaster success…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35611 – Addressable is an alternative implementation to the URI implementation that is p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35611</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35611</strong></p>
  <p>Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Templates using the * (explode) modifier with any expansion operator (e.g., {foo*}, {+var*}, {#var*}, {/va…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34827 – Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34827</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34827</strong></p>
  <p>Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using repeated String#index searches combined with String#slice! prefix deletion. For escape-heavy quoted values, this causes super-linear processing. An un…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34829 – Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34829</guid>
    <pubDate>Thu, 02 Apr 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34829</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is sent without a Content-Length header, such as with HTTP chunked transfer encoding, multipart parsing continues until end-of-stream with no total size limit. For file parts,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34785 – Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34785</guid>
    <pubDate>Thu, 02 Apr 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34785</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, fi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-187</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34060 – Ruby LSP is an implementation of the language server protocol for Ruby. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34060</guid>
    <pubDate>Tue, 31 Mar 2026 03:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34060</strong></p>
  <p>Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project containing a malicious .vscode/settings.json. This issue has been patched in Shop…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33306 – bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorith...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33306</guid>
    <pubDate>Tue, 24 Mar 2026 01:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33306</strong></p>
  <p>bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop.  Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby (`BCrypt.java`) computes the key-strengthening round count a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33176 – Active Support is a toolkit of support libraries and Ruby core extensions extrac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33176</guid>
    <pubDate>Tue, 24 Mar 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33176</strong></p>
  <p>Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33210 – Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33210</guid>
    <pubDate>Fri, 20 Mar 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33210</strong></p>
  <p>Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32698 – OpenProject is an open-source, web-based project management software. Versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32698</guid>
    <pubDate>Wed, 18 Mar 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32698</strong></p>
  <p>OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the custom field's name was injected into the SQL query without proper sanitation. This allowed an attacker to execute arbitrary SQL commands during the gene…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31830 – sigstore-ruby is a pure Ruby implementation of the sigstore verify command from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31830</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31830</strong></p>
  <p>sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the VerificationFailure returned by verify_in_toto when the artifact digest does not match the digest in the in-toto attestation subject. As a result, verification of DSSE bundles containing in-toto statements returns Verificatio…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27635 – Manyfold is an open source, self-hosted web application for managing a collectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27635</guid>
    <pubDate>Thu, 26 Feb 2026 00:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27635</strong></p>
  <p>Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.0, when model render generation is enabled, a logged-in user can achieve RCE by uploading a ZIP containing a file with a shell metacharacter in its name. The filename reaches a Ruby backtick call unsanitized. Version 0.133.0 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27614 – Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27614</guid>
    <pubDate>Wed, 25 Feb 2026 03:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27614</strong></p>
  <p>Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments returns more lines than it was given (a known upstream quirk that triggers with Ruby heredoc-style inpu…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22860 – Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22860</guid>
    <pubDate>Wed, 18 Feb 2026 19:21:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22860</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25087 – Use After Free vulnerability in Apache Arrow C++.

This issue affects Apache Arr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25087</guid>
    <pubDate>Tue, 17 Feb 2026 14:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25087</strong></p>
  <p>Use After Free vulnerability in Apache Arrow C++.  This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the tempo…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-68271 – OpenC3 COSMOS provides the functionality needed to send commands to and receive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68271</guid>
    <pubDate>Tue, 13 Jan 2026 19:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-68271</strong></p>
  <p>OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. F…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61594 – URI is a module providing classes to handle Uniform Resource Identifiers. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61594</guid>
    <pubDate>Tue, 30 Dec 2025 21:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61594</strong></p>
  <p>URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerabl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66568 – The ruby-saml library implements the client side of an SAML authorization. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66568</guid>
    <pubDate>Tue, 09 Dec 2025 16:18:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66568</strong></p>
  <p>The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66567 – The ruby-saml library is for implementing the client side of a SAML authorizatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66567</guid>
    <pubDate>Tue, 09 Dec 2025 16:18:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66567</strong></p>
  <p>The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from the same input. This allows an attacker to execute a Signature Wrapping attack. T…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61921 – Sinatra is a domain-specific language for creating web applications in Ruby. In ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61921</guid>
    <pubDate>Fri, 10 Oct 2025 20:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61921</strong></p>
  <p>Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the `etag` method is used when constructing the response. Carefully crafted input can cause `If-Match` and `If-None-Match` header parsing in Sinatra to take an unexpected am…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61919 – Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61919</guid>
    <pubDate>Fri, 10 Oct 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61919</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`, calling `rack.input.read(nil)` without enforcing a length or cap. Large request bodies can therefore be buffered completely into process memory before parsing, leading to denial of service (D…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61772 – Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61772</guid>
    <pubDate>Tue, 07 Oct 2025 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61772</strong></p>
  <p>Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header block never terminates with the required blank line (`CRLFCRLF`). The parser keeps appending incoming bytes to memory without a size cap, allowing a remote attacker to exhaust memory and cause a denial of service (DoS).…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61771 – Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61771</guid>
    <pubDate>Tue, 07 Oct 2025 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61771</strong></p>
  <p>Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) cond…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61770 – Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61770</guid>
    <pubDate>Tue, 07 Oct 2025 15:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61770</strong></p>
  <p>Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the first boundary) in memory without any size limit. A client can send a large preamble followed by a valid boundary, causing significant memory use and potential process termination due to out-of-memory (OOM) conditions. Remot…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59830 – Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::Quer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59830</guid>
    <pubDate>Thu, 25 Sep 2025 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59830</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default con…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-10026 – Spreecommerce versions prior to 0.50.x contain a remote command execution vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-10026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-10026</guid>
    <pubDate>Wed, 20 Aug 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-10026</strong></p>
  <p>Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-10026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-10019 – Spreecommerce versions prior to 0.60.2 contains a remote command execution vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-10019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-10019</guid>
    <pubDate>Wed, 13 Aug 2025 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-10019</strong></p>
  <p>Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-10019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54887 – jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54887</guid>
    <pubDate>Fri, 08 Aug 2025 01:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54887</strong></p>
  <p>jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. This puts users at risk because JWEs can be modified to decrypt to an arbitrary value, decrypted by observing parsing differences…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-45765 – ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Suppl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45765</guid>
    <pubDate>Thu, 07 Aug 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-45765</strong></p>
  <p>ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49828 – Conjur provides secrets management and application identity for infrastructure. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49828</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49828</strong></p>
  <p>Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject secrets or templates into the Secrets Manager, Self-Hosted database could take advantage of an exposed AP…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46727 – Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46727</guid>
    <pubDate>Wed, 07 May 2025 23:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46727</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. The vulnerability arises because `Rack::QueryParser` itera…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25293 – ruby-saml provides security assertion markup language (SAML) single sign-on (SSO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25293</guid>
    <pubDate>Wed, 12 Mar 2025 21:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25293</strong></p>
  <p>ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25292 – ruby-saml provides security assertion markup language (SAML) single sign-on (SSO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25292</guid>
    <pubDate>Wed, 12 Mar 2025 21:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25292</strong></p>
  <p>ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25291 – ruby-saml provides security assertion markup language (SAML) single sign-on (SSO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25291</guid>
    <pubDate>Wed, 12 Mar 2025 21:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25291</strong></p>
  <p>ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27407 – graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27407</guid>
    <pubDate>Wed, 12 Mar 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27407</strong></p>
  <p>graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, includi…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27788 – JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27788</guid>
    <pubDate>Wed, 12 Mar 2025 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27788</strong></p>
  <p>JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27610 – Rack provides an interface for developing web applications in Ruby. Prior to ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27610</guid>
    <pubDate>Mon, 10 Mar 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27610</strong></p>
  <p>Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly. The vulnerability occurs because `Rack::Static` does not properly sanitize user-supplied paths before serving files. Specific…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27111 – Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27111</guid>
    <pubDate>Tue, 04 Mar 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27111</strong></p>
  <p>Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0306 – A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0306</guid>
    <pubDate>Thu, 09 Jan 2025 04:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0306</strong></p>
  <p>A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48992 – Qualys discovered that needrestart, before version 3.8, allows local attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48992</guid>
    <pubDate>Tue, 19 Nov 2024 18:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48992</strong></p>
  <p>Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51743 – MarkUs is a web application for the submission and grading of student assignment...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51743</guid>
    <pubDate>Mon, 18 Nov 2024 20:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51743</strong></p>
  <p>MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitrary file write vulnerability in the update/upload/create file methods in Controllers allows authenticated instructors to write arbitrary files to any location on the web server MarkUs is running on (depending on the permissions of the underlying filesystem). e.g. This can lead t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51499 – MarkUs is a web application for the submission and grading of student assignment...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51499</guid>
    <pubDate>Mon, 18 Nov 2024 20:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51499</strong></p>
  <p>MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitrary file write vulnerability accessible via the update_files method of the SubmissionsController allows authenticated users (e.g. students) to write arbitrary files to any location on the web server MarkUs is running on (depending on the permissions of the underlying filesystem)…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49761 – REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49761</guid>
    <pubDate>Mon, 28 Oct 2024 15:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49761</strong></p>
  <p>REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-46986 – Camaleon CMS is a dynamic and advanced content management system based on Ruby o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46986</guid>
    <pubDate>Wed, 18 Sep 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-46986</strong></p>
  <p>Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the underlying filesystem). E.g. This can lead to a delayed remote cod…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45409 – The Ruby SAML library is for implementing the client side of a SAML authorizatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45409</guid>
    <pubDate>Tue, 10 Sep 2024 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45409</strong></p>
  <p>The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within t…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41961 – Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Ope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41961</guid>
    <pubDate>Thu, 01 Aug 2024 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41961</strong></p>
  <p>Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an `eval` sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37260 – Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37260</guid>
    <pubDate>Sat, 06 Jul 2024 10:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37260</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35231 – rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35231</guid>
    <pubDate>Mon, 27 May 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35231</strong></p>
  <p>rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of service due to the fact that the user controlled data `profiler_runs` was not constrained to any limitation. This would lead to allocating resources on the server side with no limitation and a potential denial of service by remo…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-27280 – A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27280</guid>
    <pubDate>Tue, 14 May 2024 15:11:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-27280</strong></p>
  <p>A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32970 – Phlex is a framework for building object-oriented views in Ruby. In affected ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32970</guid>
    <pubDate>Tue, 30 Apr 2024 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32970</strong></p>
  <p>Phlex is a framework for building object-oriented views in Ruby. In affected versions there is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Since the last two vulnerabilities https://github.com/phlex-ruby/phlex/security/advisories/GHSA-242p-4v39-2v8g and https://github.com/phlex-ruby/phlex/security/advisories/GHSA-g7xq-xv8c-h98c, we…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32463 – phlex is an open source framework for building object-oriented views in Ruby. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32463</guid>
    <pubDate>Wed, 17 Apr 2024 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32463</strong></p>
  <p>phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The filter to detect and prevent the use of the `javascript:` URL scheme in the `href` attribute of an `<a>` tag could be bypassed with tab `\t` or newline `\n` characters between the characters of the…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28199 – phlex is an open source framework for building object-oriented views in Ruby. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28199</guid>
    <pubDate>Mon, 11 Mar 2024 23:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28199</strong></p>
  <p>phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks. If you render an `<a>` tag with an `href` attribute set to a user-provided link, that link could potentiall…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51774 – The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of iden...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51774</guid>
    <pubDate>Thu, 29 Feb 2024 01:42:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51774</strong></p>
  <p>The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26142 – Rails is a web-application framework. Starting in version 7.1.0, there is a poss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26142</guid>
    <pubDate>Tue, 27 Feb 2024 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26142</strong></p>
  <p>Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8314 – The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8314</guid>
    <pubDate>Tue, 12 Dec 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8314</strong></p>
  <p>The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2513 – The flash_tool gem through 0.6.0 for Ruby allows command execution via shell met...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2513</guid>
    <pubDate>Tue, 12 Dec 2023 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2513</strong></p>
  <p>The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4785 – Lack of error handling in the TCP server in Google's gRPC starting version 1.23 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4785</guid>
    <pubDate>Wed, 13 Sep 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4785</strong></p>
  <p>Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40175 – Puma is a Ruby/Rack web server built for parallelism. Prior to versions 6.3.1 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40175</guid>
    <pubDate>Fri, 18 Aug 2023 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40175</strong></p>
  <p>Puma is a Ruby/Rack web server built for parallelism. Prior to versions 6.3.1 and 5.6.7, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers in a way that allowed HTTP request smuggling. Severity of this issue is highly dependent on the nature of the web site using puma is. This could be caused by either incorrect parsing of trail…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40165 – rubygems.org is the Ruby community's primary gem (library) hosting service. Insu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40165</guid>
    <pubDate>Thu, 17 Aug 2023 18:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40165</strong></p>
  <p>rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any uploaded gem version that had a platform, version number, or gem name matching `/-\d/`, permanently replacing the legitimate upload in the canonical gem storage bucket, and triggering an immediate CDN purge so that the malicious gem would be served imme…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-20108 – xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-20108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-20108</guid>
    <pubDate>Sat, 27 May 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-20108</strong></p>
  <p>xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-20108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28102 – discordrb is an implementation of the Discord API using Ruby. In discordrb befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28102</guid>
    <pubDate>Mon, 27 Mar 2023 22:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28102</strong></p>
  <p>discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` file unsafely constructs a shell string using the file parameter, which can potentially leave clients of discordrb vulnerable to command injection. The library is not directly exploitable: the exploit requires that some client of the library calls the vulnerable method with user…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36231 – pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses bac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36231</guid>
    <pubDate>Thu, 23 Feb 2023 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36231</strong></p>
  <p>pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48338 – An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-fin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48338</guid>
    <pubDate>Mon, 20 Feb 2023 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48338</strong></p>
  <p>An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby sourc…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22795 – A regular expression based DoS vulnerability in Action Dispatch &lt;6.1.7.1 and &lt;7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22795</guid>
    <pubDate>Thu, 09 Feb 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22795</strong></p>
  <p>A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerabili…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-47318 – ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47318</guid>
    <pubDate>Tue, 17 Jan 2023 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-47318</strong></p>
  <p>ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46648 – ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46648</guid>
    <pubDate>Tue, 17 Jan 2023 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46648</strong></p>
  <p>ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23476 – Nokogiri is an open source XML and HTML library for the Ruby programming languag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23476</guid>
    <pubDate>Thu, 08 Dec 2022 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23476</strong></p>
  <p>Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null pointer exception when invalid markup is being parsed. For applications using `XML::Reader` to parse untrusted inputs, this may potentially be a vect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45442 – Sinatra is a domain-specific language for creating web applications in Ruby. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45442</guid>
    <pubDate>Mon, 28 Nov 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45442</strong></p>
  <p>Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33621 – The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33621</guid>
    <pubDate>Fri, 18 Nov 2022 23:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33621</strong></p>
  <p>The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-2338 – An exploitable heap overflow vulnerability exists in the Psych::Emitter start_do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2338</guid>
    <pubDate>Thu, 29 Sep 2022 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-2338</strong></p>
  <p>An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39224 – Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39224</guid>
    <pubDate>Wed, 21 Sep 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39224</strong></p>
  <p>Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection resulting in shell execution if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the `extract` and `files` methods of the `RPM::File` class of this library. Version 0.0.12 patches these issues. A workaround for this issue is to ensure any RPMs bei…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36073 – RubyGems.org is the Ruby community gem host. A bug in password &amp; email change co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36073</guid>
    <pubDate>Wed, 07 Sep 2022 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36073</strong></p>
  <p>RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. Having access to an account whose email has been changed could enable an attacker to save API keys for that account, and when a legitimate user attempts to create an account with their email (and has to reset…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36006 – Arvados is an open source platform for managing, processing, and sharing genomic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36006</guid>
    <pubDate>Mon, 15 Aug 2022 11:21:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36006</strong></p>
  <p>Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This exists in all versions up to 2.4.1 and is fixed in 2.4.2. This vulnerability is specific to the Ruby o…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31163 – TZInfo is a Ruby library that provides access to time zone data and allows times...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31163</guid>
    <pubDate>Fri, 22 Jul 2022 04:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31163</strong></p>
  <p>TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinfo-data, are vulnerable to relative path traversal. With the Ruby data source, time zones are defined in Ruby files. There is one file per time zone. Time zone files are loaded wit…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31115 – opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31115</guid>
    <pubDate>Thu, 30 Jun 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31115</strong></p>
  <p>opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32511 – jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32511</guid>
    <pubDate>Mon, 06 Jun 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32511</strong></p>
  <p>jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33473 – An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33473</guid>
    <pubDate>Thu, 02 Jun 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33473</strong></p>
  <p>An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29181 – Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29181</guid>
    <pubDate>Fri, 20 May 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29181</strong></p>
  <p>Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-241</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25061 – The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25061</guid>
    <pubDate>Wed, 18 May 2022 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25061</strong></p>
  <p>The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-335</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30688 – needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30688</guid>
    <pubDate>Tue, 17 May 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30688</strong></p>
  <p>needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29218 – RubyGems is a package registry used to supply software for the Ruby language eco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29218</guid>
    <pubDate>Fri, 13 May 2022 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29218</strong></p>
  <p>RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a malicious package. The bug has been patched, and is believed to have never been exploited, based on an extensive review of logs…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28739 – There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28739</guid>
    <pubDate>Mon, 09 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28739</strong></p>
  <p>There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28738 – A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28738</guid>
    <pubDate>Mon, 09 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28738</strong></p>
  <p>A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29176 – Rubygems is a package registry used to supply software for the Ruby language eco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29176</guid>
    <pubDate>Thu, 05 May 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29176</strong></p>
  <p>Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed: one or more dashes in its name creation within 30 days OR no updates for over 100 days At present, we believe this vulnera…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24836 – Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `&lt; v1.13.4` c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24836</guid>
    <pubDate>Mon, 11 Apr 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24836</strong></p>
  <p>Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24790 – Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24790</guid>
    <pubDate>Wed, 30 Mar 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24790</strong></p>
  <p>Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request starts and ends. This would allow requests to be smuggled via the front-end proxy to Puma. The vulnerability has been fixe…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0759 – A flaw was found in all versions of kubeclient up to (but not including) v4.9.3,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0759</guid>
    <pubDate>Fri, 25 Mar 2022 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0759</strong></p>
  <p>A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23634 – Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23634</guid>
    <pubDate>Fri, 11 Feb 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23634</strong></p>
  <p>Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41816 – CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41816</guid>
    <pubDate>Sun, 06 Feb 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41816</strong></p>
  <p>CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41819 – CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41819</guid>
    <pubDate>Sat, 01 Jan 2022 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41819</strong></p>
  <p>CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-565</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41819">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
