Vendor Intelligence
rubygems
6 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.
CVE-2026-54603 · CVSS 8.6
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
View CVE report →
CVE-2026-45414 · CVSS 8.5
Decidim: JWT-backed authentication can be replayed across organizations
View CVE report →
CVE-2026-44025 · CVSS 7.5
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
View CVE report →
CVE-2026-47736 · CVSS 7.5
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
View CVE report →
CVE-2026-47737 · CVSS 7.5
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
View CVE report →
CVE-2026-44161 · CVSS 7.2
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
View CVE report →