Package ecosystem
RubyGems package vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 139 vulnerabilities in RubyGems packages: 4 in the last 7 days and 58 in the last 90 days, 9 of them critical and 1 exploited in the wild. The most recent, CVE-2026-77602, was published on 23 September 2026. 20 packages have a page of their own.
- Last 7 days
- 4
- Last 90 days
- 58
- Critical, all time
- 9
- Exploited in the wild
- 1
About RubyGems
The package manager and hosting service for the Ruby programming language.
RubyGems packages
- nokogiri (RubyGems)27
- rack (RubyGems)14
- oj (RubyGems)11
- jquery-rails (RubyGems)9
- jquery-ui-rails (RubyGems)8
- openc3 (RubyGems)8
- lodash-rails (RubyGems)7
- net-imap (RubyGems)7
- loofah (RubyGems)6
- action_text-trix (RubyGems)5
- camaleon_cms (RubyGems)4
- fluentd (RubyGems)4
- view_component (RubyGems)4
- websocket-driver (RubyGems)4
- alchemy_cms (RubyGems)3
- avo (RubyGems)3
- concurrent-ruby (RubyGems)3
- mpxj (RubyGems)3
- puma (RubyGems)3
- zlib (RubyGems)3
Latest RubyGems package vulnerabilities
- CVE-2026-77602: OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems…criticalCVSS 9.9EPSS 0.6%
- CVE-2026-77601: OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems…highCVSS 8.8EPSS 0.6%
- CVE-2026-65829: MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-61570: MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5…highCVSS 7.5EPSS 0.4%
- CVE-2026-44282: Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election…mediumCVSS 4.8EPSS 0.4%
- CVE-2026-44163: fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-44162: fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads…lowCVSS 2.7EPSS 0.5%
- CVE-2026-53769: Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-63435: Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-44476: Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered…mediumCVSS 6.3EPSS 0.6%
- Nokogiri unchecked return value in canonicalize methodmediumCVSS 5.3
- Nokogiri CSS selector tokenizer ReDoShighCVSS 7.5
- Nokogiri XSLT transform memory leakmediumCVSS 5.3
- CVE-2026-79772: Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-79771: Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-79770: Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer…highCVSS 7.5EPSS 0.5%
- CVE-2026-55107: Kobako sandbox escape via public_send reflectioncriticalCVSS 10
- CVE-2026-61666: websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a…highCVSS 8.9EPSS 0.4%
- CVE-2026-73428: Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to…mediumCVSS 4.6EPSS 0.4%
- CVE-2026-73427: Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to…mediumCVSS 4EPSS 0.6%
- CVE-2016-1000305: guard-livereload directory traversal in livereload servermediumCVSS 6.9
- CVE-2026-53510: Savonrb Savon code injection in Savon::ModelhighCVSS 8.1
- Basecamp ActiveRecord Tenanted path traversal in DiskServicelowCVSS 2.3
- CVE-2026-54620: sparklemotion sqlite3-ruby use-after-free in aggregate function callbackslowCVSS 2
- CVE-2026-54619: sparklemotion sqlite3-ruby use-after-free in function redefinitionlowCVSS 2
Most severe RubyGems package vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-11023: jQuery DOM manipulation XSS via option elementscriticalexploited in the wildCVSS 3.1EPSS 84.9%
- CVE-2026-55107: Kobako sandbox escape via public_send reflectioncriticalCVSS 10
- CVE-2026-77602: OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems…criticalCVSS 9.9EPSS 0.6%
- CVE-2019-11068: Nokogiri libxslt protection mechanism bypass via crafted URLcriticalCVSS 9.8EPSS 1.1%
- CVE-2026-44024: Fluent Fluentd path traversal in ${tag} placeholdercriticalCVSS 9.8
- CVE-2015-8857: UglifyJS incorrect boolean expression rewritingcriticalCVSS 9.8
- CVE-2026-42087: OpenC3 COSMOS SQL injection in QuestDB Time-Series DatabasecriticalCVSS 9.6EPSS 0.4%
- OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner ToolcriticalCVSS 9.6
- CVE-2026-39324: Rack rack-session auth bypass and deserialization in Session CookiecriticalCVSS 9.1
- CVE-2026-61666: websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a…highCVSS 8.9EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 13 | 0 | |
| 6 Jul 2026 | 6 | 1 | |
| 13 Jul 2026 | 7 | 0 | |
| 20 Jul 2026 | 5 | 0 | |
| 27 Jul 2026 | 7 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 2 | 1 | |
| 24 Aug 2026 | 7 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 3 | 0 | |
| 21 Sep 2026 | 4 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/rubygems.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "RubyGems package vulnerabilities", https://junglewise.ai/threats/vendors/rubygems, 26 September 2026.