rubygems
OSS Librariespackage-ecosystem
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting rubygems.
- CVE-2023-46035The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.5.9
- GHSA-pmwx-rm49-xv39ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
- GHSA-53g2-mvcc-q9x3Trix: Stored XSS via HTMLParser attribute injection on paste
- GHSA-cj75-f6xr-r4g7Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
- GHSA-5qhf-9phg-95m2Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
- GHSA-9wjq-cp2p-hrgfLoofah: SVG `href` attribute bypasses local-reference restriction
- GHSA-8whx-365g-h9vvLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
- GHSA-mjgf-xj26-9qf9pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
- GHSA-mqq5-j7w8-2hghAlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
- GHSA-phwj-rprq-35ppNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
- GHSA-wfpw-mmfh-qq69Nokogiri: Possible Use-After-Free in XInclude Processing
- GHSA-p67v-3w7g-wjg7Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
- GHSA-wjv4-x9w8-wm3hNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
- GHSA-5prr-v3j2-97mhNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
- GHSA-9cv2-cfxc-v4v2Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes