CVEs we hold for Ruby
Records whose assigning authority named Ruby as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-85396rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefixrubyzip
CVE-2026-71847Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key…ruby json
CVE-2026-54906concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruptionruby-concurrency concurrent-ruby
CVE-2026-54905concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivityruby-concurrency concurrent-ruby
CVE-2026-54904concurrent-ruby: `AtomicReference#update` livelocks when the stored value is `Float::NAN`ruby-concurrency concurrent-ruby
CVE-2026-54605OAuth: Cross-origin token-request redirects can expose signed request metadataruby-oauth oauth
CVE-2026-54603OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to…ruby-oauth oauth2
CVE-2026-47240Net::IMAP: Command Injection via non-synchronizing literal in "raw" argumentruby net-imap
CVE-2026-42256net-imap: Denial of service via high iteration count for `SCRAM-*` authenticationruby net-imap
CVE-2026-41316ERB has an @_init deserialization guard bypass via def_module / def_method / def_classruby erb
CVE-2026-27820zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruptionruby zlib
CVE-2024-21654rubygems.org MFA Bypass through password reset function could allow account takeoverrubygems rubygems.org
CVE-2023-40165Unauthorized gem replacement for full names ending in numbers on rubygems.orgrubygems rubygems.org
CVE-2022-36073RubyGems allows creation of users with arbitrary unverified emailsrubygems rubygems.org
CVE-2022-29218Unauthorized takeover for new versions of some platform-specific gemsrubygems rubygems.org
CVE-2021-43809Local Code Execution through Argument Injection via dash leading git url parameter in Gemfilerubygems
68 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.