Rubygems

    Dashboard / Vendors

    Products: 7
    Vulnerabilities: 37
    Known Exploited: 0
    4
    Critical Level Threats
    20
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-82455

    The RubyGems maintainers determined that the reported symlink-following behavior during gem extraction is not a security vulnerability, so no vulnerability exists for this record to describe.

    Last Modified: Sep 11, 2026
    Published: Aug 29, 2026

    CVE-2024-35221

    Denial of service when publishing a package on rubygems.org

    Last Modified: Apr 15, 2026
    Published: May 29, 2024

    CVE-2024-21654

    rubygems.org MFA Bypass through password reset function could allow account takeover

    Last Modified: Nov 21, 2024
    Published: Jan 12, 2024

    CVE-2023-40165

    Unauthorized gem replacement for full names ending in numbers on rubygems.org

    Last Modified: Nov 21, 2024
    Published: Aug 17, 2023

    CVE-2022-36073

    RubyGems allows creation of users with arbitrary unverified emails

    Last Modified: Apr 23, 2025
    Published: Sep 07, 2022
    Items Per Page
    Rubygems Vulnerabilities & Security CVEs | CVE-DB