Paperclip
This hub aggregates every CVE we track for Paperclip, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
3
Critical
0
High
0
In CISA KEV
Severity distribution
CRITICAL3MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
1
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Paperclip.
- CVE-2026-77087Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding9.6
- CVE-2026-41679Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass10.0
- CVE-2017-0889Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about inte...9.8
- CVE-2015-2963The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-si...4.3
Product normalization is registry-driven with AI assist and human review. How it works