GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,102 advisories
Filter by severity
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Low
GHSA-p67v-3w7g-wjg7
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Low
GHSA-wjv4-x9w8-wm3h
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Moderate
GHSA-5prr-v3j2-97mh
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
Low
GHSA-9cv2-cfxc-v4v2
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Low
GHSA-8678-w3jw-xfc2
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Low
GHSA-5v8h-3h3q-446p
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Critical
CVE-2026-55518
was published
for
avo
(RubyGems)
Jun 17, 2026
katello: missing repository authorization in content_uploads exposes cross-product content existence
Moderate
CVE-2026-12515
was published
for
katello
(RubyGems)
Jun 17, 2026
Net::IMAP: Command Injection via ID command argument
Moderate
CVE-2026-47242
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Denial of Service via incomplete raw argument validation
Low
CVE-2026-47241
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Moderate
CVE-2026-47240
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
High
CVE-2026-47737
was published
for
puma
(RubyGems)
Jun 9, 2026
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
High
CVE-2026-47736
was published
for
puma
(RubyGems)
Jun 8, 2026
Spree: CSV Formula Injection in Customer Export
Moderate
GHSA-xf4v-w5x5-pv79
was published
for
spree
(RubyGems)
Jun 4, 2026
Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret
Moderate
CVE-2026-44476
was published
for
doorkeeper-openid_connect
(RubyGems)
Jun 4, 2026
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
Moderate
CVE-2026-44587
was published
for
carrierwave
(RubyGems)
May 27, 2026
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
High
CVE-2026-45363
was published
for
jwt
(RubyGems)
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
Low
CVE-2026-33637
was published
for
faraday
(RubyGems)
May 18, 2026
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
Moderate
CVE-2026-44837
was published
for
view_component
(RubyGems)
May 8, 2026
view_component: Preview Route Can Dispatch Inherited Helper Methods
Moderate
CVE-2026-44836
was published
for
view_component
(RubyGems)
May 8, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
Moderate
CVE-2026-40295
was published
for
devise
(RubyGems)
May 8, 2026
Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL
Moderate
CVE-2025-67202
was published
for
sidekiq-cron
(RubyGems)
May 7, 2026
katalyst-koi: Session cookies can be replayed after user logout
High
CVE-2026-44511
was published
for
katalyst-koi
(RubyGems)
May 7, 2026
CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content
Moderate
CVE-2026-44312
was published
for
css_parser
(RubyGems)
May 7, 2026
Nokogiri XSLT transform has a memory leak
Moderate
GHSA-v2fc-qm4h-8hqv
was published
for
nokogiri
(RubyGems)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API