boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

RubyGems

Package ecosystem RubyGems. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
653

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▆█

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 0 · 2026-08 0 · 2026-09 2 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-02417.564.9—encoded_id-rails Denial of Service Vulnerability
CVE-2026-867776.944.8—AlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /api/nodes
CVE-2026-854948.734.8—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-962778.734.8—Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception
CVE-2026-946568.234.8—Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE-2026-861005.323.0—Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL

Most-affected packages

Packages with the most advisories
PackageCVEs
thrift3
camaleon_cms1
encoded_id-rails1