GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,828
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,063
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
448 advisories
Filter by severity
Active Record logging vulnerable to ANSI escape injection
Moderate
CVE-2025-55193
was published
for
activerecord
(RubyGems)
Aug 13, 2025
gRPC connection termination issue
Moderate
CVE-2023-32732
was published
for
grpc
(RubyGems)
Jul 6, 2023
Regular Expression Denial of Service (ReDoS) in lodash
Moderate
CVE-2020-28500
was published
for
lodash
(RubyGems)
Jan 6, 2022
Prototype Pollution in lodash
Moderate
CVE-2018-3721
was published
for
lodash
(RubyGems)
Jul 26, 2018
Regular Expression Denial of Service (ReDoS) in lodash
Moderate
CVE-2019-1010266
was published
for
lodash
(RubyGems)
Jul 19, 2019
Ruby SAML DOS vulnerability with large SAML response
Moderate
CVE-2025-54572
was published
for
ruby-saml
(RubyGems)
Jul 30, 2025
pubnub Insufficient Entropy vulnerability
Moderate
CVE-2023-26154
was published
for
Pubnub
(RubyGems)
Dec 6, 2023
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
Moderate
CVE-2022-31160
was published
for
jQuery.UI.Combined
(RubyGems)
Jul 18, 2022
resolv vulnerable to DoS via insufficient DNS domain name length validation
Moderate
CVE-2025-24294
was published
for
resolv
(RubyGems)
Jul 15, 2025
Measured is vulnerable to Path Traversal attacks during class initialization
Moderate
GHSA-29g5-m8v7-v564
was published
for
measured
(RubyGems)
Jul 15, 2025
HashiCorp Vagrant has code injection vulnerability through default synced folders
Moderate
CVE-2025-34075
was published
for
vagrant
(RubyGems)
Jul 2, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
Moderate
CVE-2025-6442
was published
for
webrick
(RubyGems)
Jun 26, 2025
ReDoS Vulnerability in Rack::Multipart handle_mime_head
Moderate
CVE-2025-49007
was published
for
rack
(RubyGems)
Jun 5, 2025
Duplicate Advisory: Use-after-free in libxml2 via Nokogiri::XML::Reader
Moderate
GHSA-vcc3-rw6f-jv97
was published
for
nokogiri
(RubyGems)
Mar 18, 2024
•
withdrawn
Insufficient input sanitization in ejson2env
Moderate
CVE-2025-48069
was published
for
ejson2env
(RubyGems)
May 21, 2025
Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062
Moderate
GHSA-xc9x-jj77-9p9j
was published
for
nokogiri
(RubyGems)
Feb 5, 2024
WEBrick Improper Input Validation vulnerability
Moderate
CVE-2009-4492
was published
for
webrick
(RubyGems)
Oct 24, 2017
AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field
Moderate
CVE-2018-18307
was published
for
alchemy_cms
(RubyGems)
May 14, 2022
Rack session gets restored after deletion
Moderate
CVE-2025-46336
was published
for
rack-session
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-32441
was published
for
rack
(RubyGems)
May 8, 2025
Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to
Moderate
CVE-2023-28362
was published
for
actionpack
(RubyGems)
Jun 29, 2023
Moderate severity vulnerability that affects rails
Moderate
CVE-2007-5379
was published
for
rails
(RubyGems)
Oct 24, 2017
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
Rails has possible Sensitive Session Information Leak in Active Storage
Moderate
CVE-2024-26144
was published
for
activestorage
(RubyGems)
Feb 27, 2024
ProTip!
Advisories are also available from the
GraphQL API