CVE Tools

Rubygems

889 CVEs tracked since 2006. Since Jan 2020, 1 of them reached CISA KEV.

Rubygems CVEs per month

Jan 2020 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Rubygems CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0170
2020-02100
2020-0340
2020-04null or fewer
2020-05null or fewer
2020-06100
2020-07null or fewer
2020-0840
2020-0950
2020-1040
2020-1130
2020-12null or fewer
2021-0140
2021-02110
2021-03null or fewer
2021-0460
2021-0580
2021-0670
2021-0740
2021-08null or fewer
2021-0930
2021-10120
2021-11120
2021-1250
2022-0150
2022-0250
2022-0370
2022-04110
2022-05150
2022-06130
2022-0730
2022-08null or fewer
2022-0960
2022-1060
2022-1140
2022-12170
2023-01130
2023-02131
2023-03null or fewer
2023-0460
2023-05null or fewer
2023-06100
2023-0750
2023-0850
2023-09null or fewer
2023-1050
2023-11null or fewer
2023-12120
2024-01190
2024-02140
2024-0370
2024-04null or fewer
2024-0590
2024-06null or fewer
2024-0790
2024-0860
2024-09160
2024-10120
2024-11null or fewer
2024-1270
2025-0160
2025-0250
2025-03160
2025-04null or fewer
2025-0550
2025-0660
2025-0770
2025-0860
2025-09null or fewer
2025-1060
2025-11null or fewer
2025-1270
2026-0180
2026-02120
2026-03null or fewer
2026-04100
2026-05null or fewer
2026-06100
2026-0770

Products

The products that kept showing up in Rubygems's monthly top three, with their CVEs summed over those months.

  1. Nokogiri2710 months
  2. Actionpack2013 months
  3. Rack187 months
  4. Publify_core134 months
  5. Camaleon_cms112 months
  6. Decidim116 months
  7. Rails-html-sanitizer92 months
  8. Openc382 months
  9. Loofah62 months
  10. Avo53 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Rubygems.

  1. CVE-2023-46035The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.5.9
  2. GHSA-pmwx-rm49-xv39ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal—
  3. GHSA-53g2-mvcc-q9x3Trix: Stored XSS via HTMLParser attribute injection on paste—
  4. GHSA-cj75-f6xr-r4g7Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations—
  5. GHSA-5qhf-9phg-95m2Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons—
  6. GHSA-9wjq-cp2p-hrgfLoofah: SVG `href` attribute bypasses local-reference restriction—
  7. GHSA-8whx-365g-h9vvLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references—
  8. GHSA-mjgf-xj26-9qf9pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier—
  9. GHSA-mqq5-j7w8-2hghAlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content—
  10. GHSA-phwj-rprq-35ppNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`—
  11. GHSA-wfpw-mmfh-qq69Nokogiri: Possible Use-After-Free in XInclude Processing—
  12. GHSA-p67v-3w7g-wjg7Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime—
  13. GHSA-wjv4-x9w8-wm3hNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type—
  14. GHSA-5prr-v3j2-97mhNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`—
  15. GHSA-9cv2-cfxc-v4v2Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes—

The record

Peak rank
#9 in Apr 2013
Busiest month shown
Jan 2024, 19 CVEs
Months with a KEV entry
1 since Jan 2020
Monthly snapshots
138 since 2006
Rubygems's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store