GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,143
Maven
5,000+
npm
5,000+
NuGet
840
pip
4,439
Pub
12
RubyGems
990
Rust
1,174
Swift
50
Unreviewed advisories
All unreviewed
5,000+
990 advisories
Filter by severity
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
Camaleon CMS vulnerable to Path Traversal through AWS S3 uploader implementation
Moderate
CVE-2026-1776
was published
for
camaleon_cms
(RubyGems)
Mar 10, 2026
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
Moderate
CVE-2026-25500
was published
for
rack
(RubyGems)
Feb 17, 2026
rubyipmi is vulnerable to OS Command Injection through malicious usernames
High
CVE-2026-0980
was published
for
rubyipmi
(RubyGems)
Feb 27, 2026
Rack has a Directory Traversal via Rack:Directory
High
CVE-2026-22860
was published
for
rack
(RubyGems)
Feb 17, 2026
Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-wx95-c6cv-8532
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
Sisimai Inefficient Regular Expression Complexity vulnerability
Moderate
CVE-2022-4891
was published
for
sisimai
(RubyGems)
Jan 17, 2023
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
High
CVE-2026-25757
was published
for
spree_storefront
(RubyGems)
Feb 5, 2026
Unauthenticated Spree Commerce users can access all guest addresses
High
CVE-2026-25758
was published
for
spree_api
(RubyGems)
Feb 5, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
Moderate
CVE-2026-25765
was published
for
faraday
(RubyGems)
Feb 9, 2026
Bitcoinrb Vulnerable to Command injection via RPC
Low
GHSA-q66h-m87m-j2q6
was published
for
bitcoinrb
(RubyGems)
Feb 10, 2026
Decidim's private data exports can lead to data leaks
High
CVE-2025-65017
was published
for
decidim
(RubyGems)
Feb 3, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
High
GHSA-w67g-2h6v-vjgq
was published
for
phlex
(RubyGems)
Feb 6, 2026
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
High
CVE-2026-1530
was published
for
fog-kubevirt
(RubyGems)
Feb 2, 2026
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
High
CVE-2026-1531
was published
for
foreman_kubevirt
(RubyGems)
Feb 2, 2026
Active Record component in Ruby on Rails has a data-type injection vulnerability
Critical
CVE-2013-3221
was published
for
activerecord
(RubyGems)
May 14, 2022
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
Moderate
CVE-2026-23885
was published
for
alchemy_cms
(RubyGems)
Jan 21, 2026
Active Storage allowed transformation methods that were potentially unsafe
Critical
CVE-2025-24293
was published
for
activestorage
(RubyGems)
Aug 14, 2025
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-4249-gjr8-jpq3
was published
for
prosemirror_to_html
(RubyGems)
Nov 13, 2025
•
withdrawn
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
CVE-2025-64501
was published
for
prosemirror_to_html
(RubyGems)
Nov 6, 2025
JRuby-OpenSSL has hostname verification disabled by default
Moderate
CVE-2025-46551
was published
for
jruby-openssl
(RubyGems)
May 7, 2025
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
High
GHSA-5qw5-wf2q-f538
was published
for
activerecord-jdbc-adapter
(RubyGems)
Jan 16, 2026
Active Job - Object injection security vulnerability
Moderate
GHSA-mpwp-4h2m-765c
was published
for
activejob
(RubyGems)
Jan 16, 2026
Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui gem
Moderate
CVE-2023-25309
was published
for
rollout-ui
(RubyGems)
May 11, 2023
Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapter
High
CVE-2022-44566
was published
for
activerecord
(RubyGems)
Jan 18, 2023
ProTip!
Advisories are also available from the
GraphQL API