Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
RubyGems
Package ecosystem RubyGems. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 6 | 5 | 3 |
Monthly trend
▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▆█
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 0 · 2026-08 0 · 2026-09 2 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-0241 | 7.5 | 64.9 | — | encoded_id-rails Denial of Service Vulnerability |
| CVE-2026-86777 | 6.9 | 44.8 | — | AlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /api/nodes |
| CVE-2026-85494 | 8.7 | 34.8 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-96277 | 8.7 | 34.8 | — | Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception |
| CVE-2026-94656 | 8.2 | 34.8 | — | Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound |
| CVE-2026-86100 | 5.3 | 23.0 | — | Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL |
Most-affected packages
| Package | CVEs |
|---|---|
| thrift | 3 |
| camaleon_cms | 1 |
| encoded_id-rails | 1 |