Vendor Intelligence

rubygems

6 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-54603 · CVSS 8.6

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

View CVE report →
CVE-2026-45414 · CVSS 8.5

Decidim: JWT-backed authentication can be replayed across organizations

View CVE report →
CVE-2026-44025 · CVSS 7.5

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

View CVE report →
CVE-2026-47736 · CVSS 7.5

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

View CVE report →
CVE-2026-47737 · CVSS 7.5

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

View CVE report →
CVE-2026-44161 · CVSS 7.2

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

View CVE report →