Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ruby HIGH 8.1
CVE-2026-46727

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_get…

Fix: 4.0.5+
Fix from $1,950 2026-05-22
Net\ CRITICAL 9.8
CVE-2026-42257

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::…

Fix: 0.4.24 / 0.5.14+
Fix from $2,300 2026-05-09
Net\ HIGH 7.5
CVE-2026-42245

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::Re…

Fix: 0.4.24 / 0.5.14+
Fix from $1,950 2026-05-09
Net\ HIGH 7.4
CVE-2026-42246

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man…

Fix: 0.3.10 / 0.4.24+
Fix from $1,950 2026-05-09
Net\ MEDIUM 6.5
CVE-2026-42256

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.…

Fix: 0.4.24 / 0.5.14+
Fix from $1,600 2026-05-09
Net\ MEDIUM 5.3
CVE-2026-42258

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol argume…

Fix: 0.4.24 / 0.5.14+
Fix from $1,600 2026-05-09
Zlib CRITICAL 9.8
CVE-2026-27820

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer ove…

Fix: 3.0.1 / 3.1.2+
Fix from $2,300 2026-04-16
Json CRITICAL 9.1
CVE-2026-33210

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnera…

Fix: 2.15.2.1 / 2.17.1.2+
Fix from $2,300 2026-03-20
Uri HIGH 7.5
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earl…

Fix: 0.12.5 / 0.13.3+
Fix from $1,950 2025-12-30
Rexml MEDIUM 5.3
CVE-2025-58767

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. I…

Fix: 3.4.2+
Fix from $1,600 2025-09-17
Webrick MEDIUM 5.9
CVE-2025-6442

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affec…

Fix: 1.8.2+
Fix from $1,600 2025-06-25
Net\ MEDIUM 6.5
CVE-2025-43857

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there i…

Fix: 0.2.5 / 0.3.9+
Fix from $1,600 2025-04-28
Javascript Object Notation HIGH 7.5
CVE-2025-27788

JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bo…

Fix: 2.10.2+
Fix from $1,950 2025-03-12
Cgi HIGH 7.5
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The…

Fix: 0.3.5.1 / 0.4.2+
Fix from $1,950 2025-03-04
Cgi HIGH 7.5
CVE-2025-27220

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

Fix: 0.3.5.1 / 0.4.2+
Fix from $1,950 2025-03-04
Uri MEDIUM 5.3
CVE-2025-27221

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials…

Fix: 0.11.3 / 0.12.4+
Fix from $1,600 2025-03-04
Rexml HIGH 7.5
CVE-2024-49761

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...…

Fix: 3.3.9+
Fix from $1,950 2024-10-28
Rexml MEDIUM 5.9
CVE-2024-43398

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same…

Fix: 3.3.6+
Fix from $1,600 2024-08-22
Rexml HIGH 7.5
CVE-2024-41946

REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull…

Fix: 3.3.3+
Fix from $1,950 2024-08-01
Rexml HIGH 7.5
CVE-2024-41123

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters suc…

Fix: 3.2.7 / 3.3.2+
Fix from $1,950 2024-08-01
Rexml MEDIUM 5.3
CVE-2024-35176

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an att…

Fix: 3.2.7+
Fix from $1,600 2024-05-16
Uri MEDIUM 5.3
CVE-2023-36617

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There…

Fix: 0.10.3 / 0.12.2+
Fix from $1,600 2023-06-29
Uri MEDIUM 5.3
CVE-2023-28755

A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific cha…

Fix: after 0.10.0
Fix from $1,600 2023-03-31
Ruby MEDIUM 5.3
CVE-2023-28756

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific ch…

Fix: after 2.7.7
Fix from $1,600 2023-03-31
Cgi HIGH 8.8
CVE-2021-33621

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that…

Fix: 0.1.0.2 / 0.2.2+
Fix from $1,950 2022-11-18
Ruby CRITICAL 9.8
CVE-2016-2338

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function he…

No fix yet
Fix from $2,300 2022-09-29
Ruby CRITICAL 9.8
CVE-2022-28738

A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste…

Fix: 3.0.4 / 3.1.2+
Fix from $2,300 2022-05-09
Ruby HIGH 7.5
CVE-2022-28739

There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float convers…

Fix: 2.6.10 / 2.7.6+
Fix from $1,950 2022-05-09
Cgi CRITICAL 9.8
CVE-2021-41816

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such …

Fix: 0.3.1+
Fix from $2,300 2022-02-06
Cgi HIGH 7.5
CVE-2021-41819

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Fix: 2.7.5 / 3.0.3+
Fix from $1,950 2022-01-01