GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            117 advisories
        Filter by severity
        
      
      
    
                    
                      Active Storage allowed transformation methods that were potentially unsafe
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24293
                      
                      was published
                        for
                        
                          activestorage
                        
                        (RubyGems)
                      Aug 14, 2025 
                    
                  
                    
                      JWE is missing AES-GCM authentication tag validation in encrypted JWE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54887
                      
                      was published
                        for
                        
                          jwe
                        
                        (RubyGems)
                      Aug 7, 2025 
                    
                  
                    
                      Nokogiri patches vendored libxml2 to resolve multiple CVEs
                    
                      
  Critical
                    
                
                      
                        GHSA-353f-x4gh-cqq8
                      
                      was published
                        for
                        
                          nokogiri
                        
                        (RubyGems)
                      Jul 21, 2025 
                    
                  
                    
                      Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator class
                    
                      
  Critical
                    
                
                      
                        CVE-2025-53623
                      
                      was published
                        for
                        
                          job-iteration
                        
                        (RubyGems)
                      Jul 14, 2025 
                    
                  
                    
                      OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
                    
                      
  Critical
                    
                
                      
                        CVE-2025-28384
                      
                      was published
                        for
                        
                          openc3-cosmos-tool-iframe
                        
                        (RubyGems)
                      Jun 13, 2025 
                    
                  
                    
                      Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment
                    
                      
  Critical
                    
                
                      
                        CVE-2025-2304
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Mar 14, 2025 
                    
                  
                    
                      Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25292
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25291
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
                    
                      
  Critical
                    
                
                      
                        GHSA-hw46-3hmr-x9xv
                      
                      was published
                        for
                        
                          omniauth-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      graphql allows remote code execution when loading a crafted GraphQL schema
                    
                      
  Critical
                    
                
                      
                        CVE-2025-27407
                      
                      was published
                        for
                        
                          graphql
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account
                    
                      
  Critical
                    
                
                      
                        CVE-2025-27590
                      
                      was published
                        for
                        
                          oxidized-web
                        
                        (RubyGems)
                      Mar 3, 2025 
                    
                  
                    
                      omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
                    
                      
  Critical
                    
                
                      
                        GHSA-cvp8-5r8g-fhvq
                      
                      was published
                        for
                        
                          omniauth-saml
                        
                        (RubyGems)
                      Sep 11, 2024 
                    
                  
                    
                      SAML authentication bypass via Incorrect XPath selector
                    
                      
  Critical
                    
                
                      
                        CVE-2024-45409
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Sep 10, 2024 
                    
                  
                    
                      Command Injection in sequenceserver
                    
                      
  Critical
                    
                
                      
                        CVE-2024-42360
                      
                      was published
                        for
                        
                          sequenceserver
                        
                        (RubyGems)
                      Aug 13, 2024 
                    
                  
                    
                      StringIO buffer overread vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-27280
                      
                      was published
                        for
                        
                          stringio
                        
                        (RubyGems)
                      Mar 25, 2024 
                    
                  
                    
                      discordrb OS Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-28102
                      
                      was published
                        for
                        
                          discordrb
                        
                        (RubyGems)
                      Mar 14, 2024 
                    
                  
                    
                      Puppet Bolt privilege escalation vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-5214
                      
                      was published
                        for
                        
                          bolt
                        
                        (RubyGems)
                      Oct 6, 2023 
                    
                  
                    
                      geokit-rails Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-26153
                      
                      was published
                        for
                        
                          geokit-rails
                        
                        (RubyGems)
                      Oct 6, 2023 
                    
                  
                    
                      Foreman Transpilation Enables OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2022-3874
                      
                      was published
                        for
                        
                          foreman
                        
                        (RubyGems)
                      Sep 22, 2023 
                        •
                        
                          withdrawn
                    
                  
                    
                      Puma HTTP Request/Response Smuggling vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-40175
                      
                      was published
                        for
                        
                          puma
                        
                        (RubyGems)
                      Aug 18, 2023 
                    
                  
                    
                      ruby-saml vulnerable to XPath injection
                    
                      
  Critical
                    
                
                      
                        CVE-2015-20108
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      May 27, 2023 
                    
                  
                    
                      Server-Side Template Injection in Camaleon CMS
                    
                      
  Critical
                    
                
                      
                        CVE-2023-30145
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      May 26, 2023 
                    
                  
                    
                      Buffer overflow in sponge queue functions
                    
                      
  Critical
                    
                
                      
                        CVE-2022-37454
                      
                      was published
                        for
                        
                          pysha3
                        
                        (RubyGems)
                      Apr 26, 2023 
                    
                  
                    
                      Code injection in pdf_info
                    
                      
  Critical
                    
                
                      
                        CVE-2022-36231
                      
                      was published
                        for
                        
                          pdf_info
                        
                        (RubyGems)
                      Feb 24, 2023 
                    
                  
                    
                      flash_tool Gem for Ruby File Download Handling Arbitrary Command Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2013-2513
                      
                      was published
                        for
                        
                          flash_tool
                        
                        (RubyGems)
                      Jan 26, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API