GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            117 advisories
        Filter by severity
        
      
      
    
                    
                      Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25292
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25291
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      graphql allows remote code execution when loading a crafted GraphQL schema
                    
                      
  Critical
                    
                
                      
                        CVE-2025-27407
                      
                      was published
                        for
                        
                          graphql
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
                    
                      
  Critical
                    
                
                      
                        CVE-2025-28384
                      
                      was published
                        for
                        
                          openc3-cosmos-tool-iframe
                        
                        (RubyGems)
                      Jun 13, 2025 
                    
                  
                    
                      Active Storage allowed transformation methods that were potentially unsafe
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24293
                      
                      was published
                        for
                        
                          activestorage
                        
                        (RubyGems)
                      Aug 14, 2025 
                    
                  
                    
                      Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator class
                    
                      
  Critical
                    
                
                      
                        CVE-2025-53623
                      
                      was published
                        for
                        
                          job-iteration
                        
                        (RubyGems)
                      Jul 14, 2025 
                    
                  
                    
                      Prototype Pollution in lodash
                    
                      
  Critical
                    
                
                      
                        CVE-2019-10744
                      
                      was published
                        for
                        
                          lodash
                        
                        (RubyGems)
                      Jul 10, 2019 
                    
                  
                    
                      JWE is missing AES-GCM authentication tag validation in encrypted JWE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54887
                      
                      was published
                        for
                        
                          jwe
                        
                        (RubyGems)
                      Aug 7, 2025 
                    
                  
                    
                      Nokogiri patches vendored libxml2 to resolve multiple CVEs
                    
                      
  Critical
                    
                
                      
                        GHSA-353f-x4gh-cqq8
                      
                      was published
                        for
                        
                          nokogiri
                        
                        (RubyGems)
                      Jul 21, 2025 
                    
                  
                    
                      Duplicate Advisory: Authentication Bypass by CSRF Weakness
                    
                      
  Critical
                    
                
                      
                        GHSA-gpqc-4pp7-5954
                      
                      was published
                        for
                        
                          spree_auth_devise
                        
                        (RubyGems)
                      Nov 18, 2021 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Authentication Bypass by CSRF Weakness
                    
                      
  Critical
                    
                
                      
                        GHSA-6mqr-q86q-6gwr
                      
                      was published
                        for
                        
                          spree_auth_devise
                        
                        (RubyGems)
                      Nov 18, 2021 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Authentication Bypass by CSRF Weakness
                    
                      
  Critical
                    
                
                      
                        GHSA-8xfw-5q82-3652
                      
                      was published
                        for
                        
                          spree_auth_devise
                        
                        (RubyGems)
                      Nov 18, 2021 
                        •
                        
                          withdrawn
                    
                  
                    
                      Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
                    
                      
  Critical
                    
                
                      
                        CVE-2021-41275
                      
                      was published
                        for
                        
                          spree_auth_devise
                        
                        (RubyGems)
                      Nov 18, 2021 
                    
                  
                    
                      omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
                    
                      
  Critical
                    
                
                      
                        GHSA-hw46-3hmr-x9xv
                      
                      was published
                        for
                        
                          omniauth-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
                    
                      
  Critical
                    
                
                      
                        CVE-2020-8165
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      May 26, 2020 
                    
                  
                    
                      StringIO buffer overread vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-27280
                      
                      was published
                        for
                        
                          stringio
                        
                        (RubyGems)
                      Mar 25, 2024 
                    
                  
                    
                      Bundler allows attacker to inject arbitrary code via secondary Gem source
                    
                      
  Critical
                    
                
                      
                        CVE-2016-7954
                      
                      was published
                        for
                        
                          bundler
                        
                        (RubyGems)
                      May 14, 2022 
                    
                  
                    
                      Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment
                    
                      
  Critical
                    
                
                      
                        CVE-2025-2304
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Mar 14, 2025 
                    
                  
                    
                      Code injection in pdf_info
                    
                      
  Critical
                    
                
                      
                        CVE-2022-36231
                      
                      was published
                        for
                        
                          pdf_info
                        
                        (RubyGems)
                      Feb 24, 2023 
                    
                  
                    
                      Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account
                    
                      
  Critical
                    
                
                      
                        CVE-2025-27590
                      
                      was published
                        for
                        
                          oxidized-web
                        
                        (RubyGems)
                      Mar 3, 2025 
                    
                  
                    
                      Prototype Pollution in handlebars
                    
                      
  Critical
                    
                
                      
                        CVE-2019-19919
                      
                      was published
                        for
                        
                          bootstrap-wysihtml5-rails
                        
                        (RubyGems)
                      Dec 26, 2019 
                    
                  
                    
                      ruby-saml vulnerable to XPath injection
                    
                      
  Critical
                    
                
                      
                        CVE-2015-20108
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      May 27, 2023 
                    
                  
                    
                      netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
                    
                      
  Critical
                    
                
                      
                        CVE-2019-17383
                      
                      was published
                        for
                        
                          netaddr
                        
                        (RubyGems)
                      Oct 14, 2019 
                    
                  
                    
                      omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
                    
                      
  Critical
                    
                
                      
                        GHSA-cvp8-5r8g-fhvq
                      
                      was published
                        for
                        
                          omniauth-saml
                        
                        (RubyGems)
                      Sep 11, 2024 
                    
                  
                    
                      SAML authentication bypass via Incorrect XPath selector
                    
                      
  Critical
                    
                
                      
                        CVE-2024-45409
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Sep 10, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API