Vendor Intelligence

rubygems

5 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-45414 · CVSS 8.5

Decidim: JWT-backed authentication can be replayed across organizations

View CVE report →
CVE-2026-44025 · CVSS 7.5

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

View CVE report →
CVE-2026-47736 · CVSS 7.5

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

View CVE report →
CVE-2026-47737 · CVSS 7.5

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

View CVE report →
CVE-2026-44161 · CVSS 7.2

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

View CVE report →