| concurrent-ruby |
CVE-2026-54906 |
严重 |
1.2.3 |
>= 1.3.7 |
concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of service
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54906
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:00
|
| concurrent-ruby |
CVE-2026-54906 |
严重 |
1.3.6 |
>= 1.3.7 |
concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of service
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54906
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:00
|
| net-imap |
CVE-2026-42257 |
严重 |
0.4.21 |
~> 0.4.24, ~> 0.5.14, >= 0.6.4 |
net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42257
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-09 20:16 修改: 2026-06-17 10:47
|
| concurrent-ruby |
CVE-2026-54904 |
高危 |
1.2.3 |
>= 1.3.7 |
concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#update
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54904
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 19:26
|
| addressable |
CVE-2026-35611 |
高危 |
2.8.7 |
>= 2.9.0 |
addressable: Addressable: Denial of Service via crafted URI templates
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35611
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-04-07 17:16 修改: 2026-06-17 10:40
|
| concurrent-ruby |
CVE-2026-54904 |
高危 |
1.3.6 |
>= 1.3.7 |
concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#update
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54904
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 19:26
|
| erb |
CVE-2026-41316 |
高危 |
4.0.3 |
~> 4.0.3.1, ~> 4.0.4.1, ~> 6.0.1.1, >= 6.0.4 |
erb: ERB: Arbitrary code execution via deserialization bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41316
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-04-24 03:16 修改: 2026-06-17 10:46
|
| faraday |
CVE-2026-54297 |
高危 |
2.14.1 |
>= 2.14.3 |
faraday: Faraday: Denial of Service via crafted nested query strings
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54297
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:01
|
| faraday |
CVE-2026-54297 |
高危 |
2.14.2 |
>= 2.14.3 |
faraday: Faraday: Denial of Service via crafted nested query strings
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54297
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:01
|
| faraday |
CVE-2026-54297 |
高危 |
2.8.1 |
>= 2.14.3 |
faraday: Faraday: Denial of Service via crafted nested query strings
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54297
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:01
|
| activesupport |
CVE-2026-33176 |
高危 |
7.0.8.4 |
~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 |
Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33176
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-03-24 00:16 修改: 2026-06-17 10:37
|
| net-imap |
CVE-2026-42245 |
高危 |
0.4.21 |
~> 0.4.24, ~> 0.5.14, >= 0.6.4 |
ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42245
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-09 20:16 修改: 2026-06-17 10:47
|
| net-imap |
CVE-2026-42246 |
高危 |
0.4.21 |
~> 0.3.10, ~> 0.4.24, ~> 0.5.14, >= 0.6.4 |
net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42246
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-09 20:16 修改: 2026-06-17 10:47
|
| oauth |
GHSA-prq8-7wvh-44qh |
高危 |
0.5.6 |
>= 1.1.6 |
Cross-origin OAuth token-request redirects can expose signed request metadata
漏洞详情: https://github.com/advisories/GHSA-prq8-7wvh-44qh
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| oauth2 |
GHSA-pp92-crg2-gfv9 |
高危 |
2.0.20 |
>= 2.0.22 |
Protocol-relative redirect Location overrides authority in OAuth2::Client#request, leaking bearer Authorization to attacker host
漏洞详情: https://github.com/advisories/GHSA-pp92-crg2-gfv9
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| puma |
CVE-2026-47736 |
高危 |
8.0.1 |
~> 7.2.1, >= 8.0.2 |
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47736
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| puma |
CVE-2026-47737 |
高危 |
8.0.1 |
~> 7.2.1, >= 8.0.2 |
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47737
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| sinatra |
CVE-2025-61921 |
高危 |
3.2.0 |
>= 4.2.0 |
sinatra: Sinatra has ReDoS vulnerability in ETag header value generation
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61921
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2025-10-10 20:15 修改: 2026-06-17 09:51
|
| carrierwave |
CVE-2024-29034 |
中危 |
1.3.4 |
~> 2.2.6, >= 3.0.7 |
CarrierWave content-Type allowlist bypass vulnerability which possibly leads to XSS remained
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29034
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2024-03-24 20:15 修改: 2026-06-17 07:22
|
| excon |
CVE-2026-54171 |
中危 |
1.3.0 |
>= 1.5.0 |
redact additional sensitive/risky headers when following redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54171
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| carrierwave |
CVE-2026-44587 |
中危 |
1.3.4 |
~> 2.2.7, >= 3.1.3 |
CarrierWave is a framework to upload files from Ruby applications. In ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44587
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-17 13:20 修改: 2026-06-18 15:24
|
| faraday |
CVE-2026-33637 |
中危 |
2.14.1 |
>= 2.14.2 |
faraday: rubygem-faraday: Faraday: Off-host request forgery due to protocol-relative host override
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33637
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-19 19:16 修改: 2026-06-17 10:37
|
| activesupport |
CVE-2026-33170 |
中危 |
7.0.8.4 |
~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 |
Rails: Active Support: Active Support: Cross-Site Scripting (XSS) due to improper HTML safety flag propagation in SafeBuffer#%
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33170
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-03-24 00:16 修改: 2026-06-17 10:37
|
| activesupport |
CVE-2026-33169 |
中危 |
7.0.8.4 |
~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 |
rails: rails-activesupport: Active Support: Denial of Service via crafted long digit strings
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33169
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-03-24 00:16 修改: 2026-06-17 10:37
|
| faraday |
CVE-2026-25765 |
中危 |
2.8.1 |
~> 1.10.5, >= 2.14.1 |
Faraday: Faraday: Server-Side Request Forgery via protocol-relative URLs
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25765
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-02-09 21:15 修改: 2026-06-17 10:25
|
| faraday |
CVE-2026-33637 |
中危 |
2.8.1 |
>= 2.14.2 |
faraday: rubygem-faraday: Faraday: Off-host request forgery due to protocol-relative host override
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33637
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-19 19:16 修改: 2026-06-17 10:37
|
| concurrent-ruby |
CVE-2026-54905 |
中危 |
1.2.3 |
>= 1.3.7 |
concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54905
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:01
|
| aws-sdk-s3 |
CVE-2025-14762 |
中危 |
1.149.1 |
>= 1.208.0 |
aws-sdk-ruby: AWS SDK for Ruby: Data integrity compromise via missing cryptographic key commitment
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14762
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2025-12-17 21:15 修改: 2026-06-17 08:36
|
| carrierwave |
CVE-2023-49090 |
中危 |
1.3.4 |
~> 2.2.5, >= 3.0.5 |
CarrierWave is a solution for file uploads for Rails, Sinatra and othe ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-49090
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2023-11-29 15:15 修改: 2026-06-17 06:35
|
| net-imap |
CVE-2026-42256 |
中危 |
0.4.21 |
~> 0.4.24, ~> 0.5.14, >= 0.6.4 |
ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42256
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-09 20:16 修改: 2026-06-17 10:47
|
| net-imap |
CVE-2026-42258 |
中危 |
0.4.21 |
~> 0.4.24, ~> 0.5.14, >= 0.6.4 |
ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42258
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-09 20:16 修改: 2026-06-26 18:32
|
| net-imap |
CVE-2026-47240 |
中危 |
0.4.21 |
~> 0.5.15, >= 0.6.4.1 |
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47240
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-22 21:16 修改: 2026-06-23 16:16
|
| net-imap |
CVE-2026-47242 |
中危 |
0.4.21 |
~> 0.5.15, >= 0.6.4.1 |
Net::IMAP: Command Injection via ID command argument
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47242
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-22 21:16 修改: 2026-06-23 15:03
|
| net-imap |
CVE-2026-47240 |
中危 |
0.6.4 |
~> 0.5.15, >= 0.6.4.1 |
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47240
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-22 21:16 修改: 2026-06-23 16:16
|
| net-imap |
CVE-2026-47242 |
中危 |
0.6.4 |
~> 0.5.15, >= 0.6.4.1 |
Net::IMAP: Command Injection via ID command argument
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47242
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-22 21:16 修改: 2026-06-23 15:03
|
| nokogiri |
GHSA-5prr-v3j2-97mh |
中危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
漏洞详情: https://github.com/advisories/GHSA-5prr-v3j2-97mh
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:36 修改: 2026-06-19 16:36
|
| concurrent-ruby |
CVE-2026-54905 |
中危 |
1.3.6 |
>= 1.3.7 |
concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54905
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-24 17:17 修改: 2026-06-26 20:01
|
| css_parser |
CVE-2026-44312 |
中危 |
1.14.0 |
~> 1.22.0, >= 2.1.0 |
css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Pa ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44312
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-14 17:16 修改: 2026-06-17 10:50
|
| devise |
CVE-2026-32700 |
中危 |
4.9.4 |
>= 5.0.3 |
devise: Devise: Unauthorized email confirmation due to a race condition
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32700
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-03-18 21:16 修改: 2026-06-17 10:36
|
| devise |
CVE-2026-40295 |
中危 |
4.9.4 |
>= 5.0.4 |
Devise is an authentication solution for Rails based on Warden. In ver ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40295
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-22 20:16 修改: 2026-06-17 10:44
|
| sidekiq-cron |
CVE-2025-67202 |
中危 |
2.3.1 |
>= 2.4.0 |
sidekiq-cron: Sidekiq-cron: Cross-site scripting vulnerability via crafted URL
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67202
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-07 15:16 修改: 2026-06-17 09:57
|
| doorkeeper-openid_connect |
CVE-2026-44476 |
中危 |
1.9.0 |
>= 1.10.0 |
Dynamic Client Registration feature creates public clients with client_secret
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44476
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| sinatra |
CVE-2024-21510 |
中危 |
3.2.0 |
>= 4.1.0 |
sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21510
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2024-11-01 05:15 修改: 2026-06-17 07:09
|
| view_component |
CVE-2026-44836 |
中危 |
3.23.2 |
>= 4.9.0, >= 3.25.0, < 4.0.0 |
view_component is a framework for building reusable, testable, and enc ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44836
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-26 21:16 修改: 2026-06-17 10:51
|
| view_component |
CVE-2026-44837 |
中危 |
3.23.2 |
>= 4.9.0, >= 3.25.0, < 4.0.0 |
view_component is a framework for building reusable, testable, and enc ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44837
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-05-26 21:16 修改: 2026-06-17 10:51
|
| net-imap |
CVE-2026-47241 |
低危 |
0.6.4 |
~> 0.5.15, >= 0.6.4.1 |
Net::IMAP: Denial of Service via incomplete raw argument validation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47241
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-22 21:16 修改: 2026-06-23 15:16
|
| net-imap |
CVE-2026-47241 |
低危 |
0.4.21 |
~> 0.5.15, >= 0.6.4.1 |
Net::IMAP: Denial of Service via incomplete raw argument validation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47241
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-22 21:16 修改: 2026-06-23 15:16
|
| nokogiri |
GHSA-5v8h-3h3q-446p |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
漏洞详情: https://github.com/advisories/GHSA-5v8h-3h3q-446p
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:35 修改: 2026-06-19 16:35
|
| nokogiri |
GHSA-8678-w3jw-xfc2 |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
漏洞详情: https://github.com/advisories/GHSA-8678-w3jw-xfc2
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:36 修改: 2026-06-19 16:36
|
| nokogiri |
GHSA-9cv2-cfxc-v4v2 |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
漏洞详情: https://github.com/advisories/GHSA-9cv2-cfxc-v4v2
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:36 修改: 2026-06-19 16:36
|
| nokogiri |
GHSA-p67v-3w7g-wjg7 |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
漏洞详情: https://github.com/advisories/GHSA-p67v-3w7g-wjg7
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:37 修改: 2026-06-19 16:37
|
| nokogiri |
GHSA-phwj-rprq-35pp |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
漏洞详情: https://github.com/advisories/GHSA-phwj-rprq-35pp
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:37 修改: 2026-06-19 16:37
|
| thor |
CVE-2025-54314 |
低危 |
1.2.2 |
>= 1.4.0 |
thor: Thor Command Injection Vulnerability
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-54314
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2025-07-20 03:15 修改: 2026-06-17 09:39
|
| nokogiri |
GHSA-wfpw-mmfh-qq69 |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Possible Use-After-Free in XInclude Processing
漏洞详情: https://github.com/advisories/GHSA-wfpw-mmfh-qq69
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:37 修改: 2026-06-19 16:37
|
| nokogiri |
GHSA-wjv4-x9w8-wm3h |
低危 |
1.19.3 |
>= 1.19.4 |
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
漏洞详情: https://github.com/advisories/GHSA-wjv4-x9w8-wm3h
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 2026-06-19 16:36 修改: 2026-06-19 16:36
|
| nokogiri |
GHSA-g9g8-vgvw-g3vf |
未知 |
1.19.3 |
>= 1.19.4 |
Possible invalid memory read when calling `Nokogiri::XML::Node#initialize_copy_with_args` with incorrect argument type
漏洞详情: https://github.com/advisories/GHSA-g9g8-vgvw-g3vf
镜像层: sha256:ea5bbd63e8bcf35bd42fedbc793c784acc5659d048ca3c4f3e31c7c60bf19a0d
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|