{"schema_version":1,"title":"RubyGems package vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 377 vulnerabilities in RubyGems packages: 4 in the last 7 days and 69 in the last 90 days, 13 of them critical and 2 exploited in the wild. The most recent, CVE-2026-77602, was published on 23 September 2026. 20 packages have a page of their own.","url":"https://junglewise.ai/threats/vendors/rubygems","json_url":"https://junglewise.ai/threats/vendors/rubygems.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/rubygems","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":38,"all_time":377,"critical":13,"exploited":2,"last_7_days":4,"last_30_days":10,"last_90_days":69,"last_365_days":121},"latest":[{"cve":"CVE-2026-77602","cvss":9.9,"epss":0.0057,"slug":"cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3","severity":"critical","exploited":false,"published_at":"2026-09-23T19:19:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config"},{"cve":"CVE-2026-77601","cvss":8.8,"epss":0.0058,"slug":"cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.","severity":"high","exploited":false,"published_at":"2026-09-23T19:19:18.38+00:00","url":"https://junglewise.ai/threats/cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url"},{"cve":"CVE-2026-65829","cvss":5.3,"epss":0.0034,"slug":"cve-2026-65829-mpxj-path-traversal-in-primavera-p3-prx-and-suretrak-stx-readers","title":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, readin","severity":"medium","exploited":false,"published_at":"2026-09-22T20:17:05.06+00:00","url":"https://junglewise.ai/threats/cve-2026-65829-mpxj-path-traversal-in-primavera-p3-prx-and-suretrak-stx-readers"},{"cve":"CVE-2026-61570","cvss":7.5,"epss":0.0035,"slug":"cve-2026-61570-mpxj-xxe-vulnerability-in-merlinreader","title":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, Merlin","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:04.287+00:00","url":"https://junglewise.ai/threats/cve-2026-61570-mpxj-xxe-vulnerability-in-merlinreader"},{"cve":"CVE-2026-44282","cvss":4.8,"epss":0.0039,"slug":"cve-2026-44282-decidim-decidim-elections-stored-xss-in-question-titles","title":"Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with questi","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:09.96+00:00","url":"https://junglewise.ai/threats/cve-2026-44282-decidim-decidim-elections-stored-xss-in-question-titles"},{"cve":"CVE-2026-44163","cvss":5.3,"epss":0.0042,"slug":"cve-2026-44163-fluentd-fluent-plugin-opentelemetry-dos-in-in-opentelemetry-http","title":"fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentele","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:09.823+00:00","url":"https://junglewise.ai/threats/cve-2026-44163-fluentd-fluent-plugin-opentelemetry-dos-in-in-opentelemetry-http"},{"cve":"CVE-2026-44162","cvss":2.7,"epss":0.0048,"slug":"cve-2026-44162-fluentd-fluent-plugin-s3-denial-of-service-via-decompression-bomb","title":"fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompres","severity":"low","exploited":false,"published_at":"2026-09-14T18:17:47.513+00:00","url":"https://junglewise.ai/threats/cve-2026-44162-fluentd-fluent-plugin-s3-denial-of-service-via-decompression-bomb"},{"cve":"CVE-2023-46035","cvss":5.9,"epss":0.0036,"slug":"cve-2023-46035-svg-optimizer-gem-xml-entity-expansion-in-svg-parsing","title":"svg_optimizer gem XML entity expansion in SVG parsing","severity":"medium","exploited":false,"published_at":"2026-09-14T06:16:54.5+00:00","url":"https://junglewise.ai/threats/cve-2023-46035-svg-optimizer-gem-xml-entity-expansion-in-svg-parsing"},{"cve":"CVE-2026-53769","cvss":6.5,"epss":0.0042,"slug":"cve-2026-53769-avo-missing-upload-authorization-in-attachmentscontroller","title":"Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment uplo","severity":"medium","exploited":false,"published_at":"2026-09-04T21:17:25.3+00:00","url":"https://junglewise.ai/threats/cve-2026-53769-avo-missing-upload-authorization-in-attachmentscontroller"},{"cve":"CVE-2026-63435","cvss":5.3,"epss":0.0045,"slug":"cve-2026-63435-mail-email-address-spoofing-via-malformed-rfc-2047-encoded-words","title":"Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_deco","severity":"medium","exploited":false,"published_at":"2026-09-01T21:18:35.287+00:00","url":"https://junglewise.ai/threats/cve-2026-63435-mail-email-address-spoofing-via-malformed-rfc-2047-encoded-words"},{"cve":"CVE-2026-44476","cvss":6.3,"epss":0.0056,"slug":"cve-2026-44476-doorkeeper-openid-connect-authentication-bypass-in-dynamic-client","title":"Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_i","severity":"medium","exploited":false,"published_at":"2026-08-25T23:17:04.4+00:00","url":"https://junglewise.ai/threats/cve-2026-44476-doorkeeper-openid-connect-authentication-bypass-in-dynamic-client"},{"cvss":5.3,"slug":"nokogiri-unchecked-return-value-in-canonicalize-method-3863de91","title":"Nokogiri unchecked return value in canonicalize method","severity":"medium","exploited":false,"published_at":"2026-08-25T18:31:53+00:00","url":"https://junglewise.ai/threats/nokogiri-unchecked-return-value-in-canonicalize-method-3863de91"},{"cvss":5.3,"slug":"nokogiri-xslt-transform-memory-leak-0441ddf7","title":"Nokogiri XSLT transform memory leak","severity":"medium","exploited":false,"published_at":"2026-08-25T18:31:52+00:00","url":"https://junglewise.ai/threats/nokogiri-xslt-transform-memory-leak-0441ddf7"},{"cvss":3.1,"slug":"duplicate-advisory-nokogiri-css-selector-tokenizer-has-regular-3dc091bb","title":"Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking","severity":"low","exploited":false,"published_at":"2026-08-25T18:31:52+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-nokogiri-css-selector-tokenizer-has-regular-3dc091bb"},{"cvss":7.5,"slug":"nokogiri-css-selector-tokenizer-redos-d52ae203","title":"Nokogiri CSS selector tokenizer ReDoS","severity":"high","exploited":false,"published_at":"2026-08-25T18:31:52+00:00","url":"https://junglewise.ai/threats/nokogiri-css-selector-tokenizer-redos-d52ae203"},{"cve":"CVE-2026-79772","cvss":5.3,"epss":0.0034,"slug":"cve-2026-79772-nokogiri-cruby-unchecked-return-value-in-canonicalize","title":"Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on","severity":"medium","exploited":false,"published_at":"2026-08-25T16:17:28.743+00:00","url":"https://junglewise.ai/threats/cve-2026-79772-nokogiri-cruby-unchecked-return-value-in-canonicalize"},{"cve":"CVE-2026-79771","cvss":5.3,"epss":0.0042,"slug":"cve-2026-79771-nokogiri-xslt-stylesheet-transform-memory-leak","title":"Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null b","severity":"medium","exploited":false,"published_at":"2026-08-25T16:17:28.603+00:00","url":"https://junglewise.ai/threats/cve-2026-79771-nokogiri-xslt-stylesheet-transform-memory-leak"},{"cve":"CVE-2026-79770","cvss":7.5,"epss":0.0049,"slug":"cve-2026-79770-nokogiri-css-selector-tokenizer-regular-expression-dos","title":"Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string","severity":"high","exploited":false,"published_at":"2026-08-25T16:17:28.46+00:00","url":"https://junglewise.ai/threats/cve-2026-79770-nokogiri-css-selector-tokenizer-regular-expression-dos"},{"cve":"CVE-2025-71346","slug":"cve-2025-71346-duplicate-rejected-advisory","title":"duplicate rejected advisory","severity":"info","exploited":false,"published_at":"2026-08-25T16:16:45.32+00:00","url":"https://junglewise.ai/threats/cve-2025-71346-duplicate-rejected-advisory"},{"cve":"CVE-2022-50998","slug":"cve-2022-50998-duplicate-rejected","title":"duplicate rejected","severity":"info","exploited":false,"published_at":"2026-08-25T16:16:44.073+00:00","url":"https://junglewise.ai/threats/cve-2022-50998-duplicate-rejected"},{"cve":"CVE-2021-47996","slug":"cve-2021-47996-duplicate-rejection","title":"duplicate rejection","severity":"info","exploited":false,"published_at":"2026-08-25T16:16:42.93+00:00","url":"https://junglewise.ai/threats/cve-2021-47996-duplicate-rejection"},{"cve":"CVE-2026-55107","cvss":10,"slug":"cve-2026-55107-kobako-sandbox-escape-via-public-send-reflection","title":"Kobako sandbox escape via public_send reflection","severity":"critical","exploited":false,"published_at":"2026-08-18T20:09:59+00:00","url":"https://junglewise.ai/threats/cve-2026-55107-kobako-sandbox-escape-via-public-send-reflection"},{"cve":"CVE-2026-61666","cvss":4,"epss":0.0045,"slug":"cve-2026-61666-faye-websocket-driver-ruby-denial-of-service-via-malformed-host","title":"websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host head","severity":"high","exploited":false,"published_at":"2026-08-17T17:16:39.917+00:00","url":"https://junglewise.ai/threats/cve-2026-61666-faye-websocket-driver-ruby-denial-of-service-via-malformed-host"},{"cve":"CVE-2026-73428","cvss":4.6,"epss":0.0035,"slug":"cve-2026-73428-basecamp-trix-stored-xss-via-htmlparser-attribute-injection-on","title":"Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scrip","severity":"medium","exploited":false,"published_at":"2026-08-13T22:17:26.587+00:00","url":"https://junglewise.ai/threats/cve-2026-73428-basecamp-trix-stored-xss-via-htmlparser-attribute-injection-on"},{"cve":"CVE-2026-73492","cvss":4,"epss":0.0039,"slug":"cve-2026-73492-loofah-xss-via-malformed-uri-scheme-with-numeric-character","title":"Loofah XSS via malformed URI scheme with numeric character references","severity":"medium","exploited":false,"published_at":"2026-08-12T22:17:16.527+00:00","url":"https://junglewise.ai/threats/cve-2026-73492-loofah-xss-via-malformed-uri-scheme-with-numeric-character"}],"vendor":{"hub":true,"name":"RubyGems","slug":"rubygems","homepage":"https://rubygems.org/","ecosystem":"RubyGems","description":"The package manager and hosting service for the Ruby programming language.","url":"https://junglewise.ai/threats/vendors/rubygems"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":13},{"week":"2026-07-06","critical":1,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2023-0669","cvss":3.1,"epss":1,"slug":"cve-2023-0669-fortra-goanywhere-mft-remote-code-execution-vulnerability","title":"Withdrawn: Fortra GoAnywhere MFT Deserialization of Untrusted Data vulnerability affects metasploit-framework","severity":"critical","exploited":true,"published_at":"2023-02-06T21:30:29+00:00","url":"https://junglewise.ai/threats/cve-2023-0669-fortra-goanywhere-mft-remote-code-execution-vulnerability"},{"cve":"CVE-2020-11023","cvss":3.1,"epss":0.8489,"slug":"cve-2020-11023-jquery-cross-site-scripting-xss-vulnerability","title":"jQuery DOM manipulation XSS via option elements","severity":"critical","exploited":true,"published_at":"2020-04-29T22:19:14+00:00","url":"https://junglewise.ai/threats/cve-2020-11023-jquery-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2026-55107","cvss":10,"slug":"cve-2026-55107-kobako-sandbox-escape-via-public-send-reflection","title":"Kobako sandbox escape via public_send reflection","severity":"critical","exploited":false,"published_at":"2026-08-18T20:09:59+00:00","url":"https://junglewise.ai/threats/cve-2026-55107-kobako-sandbox-escape-via-public-send-reflection"},{"cve":"CVE-2026-77602","cvss":9.9,"epss":0.0057,"slug":"cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3","severity":"critical","exploited":false,"published_at":"2026-09-23T19:19:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config"},{"cve":"CVE-2022-32511","cvss":9.8,"epss":0.0243,"slug":"cve-2022-32511-jmespath-for-ruby-unsafe-deserialization-in-jmespath-rb","title":"JMESPath for Ruby unsafe deserialization in jmespath.rb","severity":"critical","exploited":false,"published_at":"2022-06-07T00:00:31+00:00","url":"https://junglewise.ai/threats/cve-2022-32511-jmespath-for-ruby-unsafe-deserialization-in-jmespath-rb"},{"cve":"CVE-2019-11068","cvss":9.8,"epss":0.0113,"slug":"cve-2019-11068-nokogiri-libxslt-protection-mechanism-bypass-via-crafted-url","title":"Nokogiri libxslt protection mechanism bypass via crafted URL","severity":"critical","exploited":false,"published_at":"2022-05-13T01:21:57+00:00","url":"https://junglewise.ai/threats/cve-2019-11068-nokogiri-libxslt-protection-mechanism-bypass-via-crafted-url"},{"cve":"CVE-2026-44024","cvss":9.8,"epss":0.0109,"slug":"cve-2026-44024-fluent-fluentd-path-traversal-in-tag-placeholder","title":"Fluent Fluentd path traversal in ${tag} placeholder","severity":"critical","exploited":false,"published_at":"2026-07-08T22:17:14.337+00:00","url":"https://junglewise.ai/threats/cve-2026-44024-fluent-fluentd-path-traversal-in-tag-placeholder"},{"cve":"CVE-2015-8857","cvss":9.8,"slug":"cve-2015-8857-uglifyjs-incorrect-boolean-expression-rewriting","title":"UglifyJS incorrect boolean expression rewriting","severity":"critical","exploited":false,"published_at":"2017-01-23T21:59:00.58+00:00","url":"https://junglewise.ai/threats/cve-2015-8857-uglifyjs-incorrect-boolean-expression-rewriting"},{"cve":"CVE-2026-42088","cvss":9.6,"epss":0.0049,"slug":"cve-2026-42088-openc3-cosmos-privilege-escalation-via-script-runner-api-bypass","title":"OpenC3 COSMOS privilege escalation via Script Runner API bypass","severity":"critical","exploited":false,"published_at":"2026-05-04T18:16:31.007+00:00","url":"https://junglewise.ai/threats/cve-2026-42088-openc3-cosmos-privilege-escalation-via-script-runner-api-bypass"},{"cve":"CVE-2026-42087","cvss":9.6,"epss":0.0045,"slug":"cve-2026-42087-openc3-cosmos-sql-injection-in-questdb-time-series-database","title":"OpenC3 COSMOS SQL injection in QuestDB Time-Series Database","severity":"critical","exploited":false,"published_at":"2026-04-23T14:12:02+00:00","url":"https://junglewise.ai/threats/cve-2026-42087-openc3-cosmos-sql-injection-in-questdb-time-series-database"}],"generated_at":"2026-09-26T16:07:00.132667+00:00","technologies":[{"name":"nokogiri (RubyGems)","slug":"nokogiri","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/nokogiri"},{"name":"rack (RubyGems)","slug":"rack","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rack"},{"name":"oj (RubyGems)","slug":"oj","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"name":"jquery-rails (RubyGems)","slug":"jquery-rails","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/jquery-rails"},{"name":"jquery-ui-rails (RubyGems)","slug":"jquery-ui-rails","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/jquery-ui-rails"},{"name":"openc3 (RubyGems)","slug":"openc3","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/openc3"},{"name":"lodash-rails (RubyGems)","slug":"lodash-rails","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/lodash-rails"},{"name":"net-imap (RubyGems)","slug":"net-imap","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/net-imap"},{"name":"loofah (RubyGems)","slug":"loofah","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/loofah"},{"name":"action_text-trix (RubyGems)","slug":"action-text-trix","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/action-text-trix"},{"name":"camaleon_cms (RubyGems)","slug":"camaleon-cms","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/camaleon-cms"},{"name":"fluentd (RubyGems)","slug":"fluentd","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/fluentd"},{"name":"view_component (RubyGems)","slug":"view-component","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/view-component"},{"name":"websocket-driver (RubyGems)","slug":"websocket-driver","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/websocket-driver"},{"name":"alchemy_cms (RubyGems)","slug":"alchemy-cms","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/alchemy-cms"},{"name":"avo (RubyGems)","slug":"avo","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/avo"},{"name":"concurrent-ruby (RubyGems)","slug":"concurrent-ruby","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/concurrent-ruby"},{"name":"mpxj (RubyGems)","slug":"mpxj","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/mpxj"},{"name":"puma (RubyGems)","slug":"puma","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/puma"},{"name":"zlib (RubyGems)","slug":"zlib","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/zlib"}]}