
Community-maintained database of security advisories for Ruby gems and runtimes, providing structured CVE/GHSA data with patched versions for vulnerability tracking and audit integration.
The Ruby Advisory Database is a community effort to compile all security advisories that are relevant to Ruby libraries. We expect others to create the data, such as getting CVE's, GHSA's, OSVDB's, cvss', or original vulnerability information. More details at HERE.
You can check your own Gemfile.locks against this database by using bundler-audit.
Do you know about a vulnerability that isn't listed in this database? Open an issue or submit a PR.
The database is a list of directories that match the names of Ruby libraries on rubygems.org. Within each directory are one or more advisory files for the Ruby library. These advisory files are named using the advisories' CVE or GHSA or OSVDB (legacy) identifier number.
gems/:
actionpack/:
CVE-2014-0130.yml CVE-2014-7818.yml CVE-2014-7829.yml CVE-2015-7576.yml
CVE-2015-7581.yml CVE-2016-0751.yml CVE-2016-0752.yml
rubies/:
jruby/:
...
mruby/:
...
ruby/:
...
gems/The gems/ directory contains sub-directories that match the names of the Ruby
libraries on rubygems.org. Within each directory are one or more advisory
files for the Ruby library. These advisory files are named using the
advisories' CVE or GHSA ID.
rubies/The rubies/ directory contains sub-directories for each Ruby implementation.
Within each directory are one or more advisory files for the Ruby
implementation. These advisory files are named using the advisories' CVE
or GHSA ID.
Each advisory file contains the advisory information in YAML format. Here are some example advisories:
gems/actionpack/CVE-2023-22795.yml---
gem: actionpack
cve: 2023-22795
ghsa: 8xww-x3g3-6jcv
url: https://github.com/rails/rails/releases/tag/v7.0.4.1
title: ReDoS based DoS vulnerability in Action Dispatch
date: 2023-01-18
description: |
There is a possible regular expression based DoS vulnerability in Action
Dispatch related to the If-None-Match header. This vulnerability has been
assigned the CVE identifier CVE-2023-22795.
Versions Affected: All
Not affected: None
Fixed Versions: 6.1.7.1, 7.0.4.1
# Impact
A specially crafted HTTP If-None-Match header can cause the regular
expression engine to enter a state of catastrophic backtracking, when on a
version of Ruby below 3.2.0. This can cause the process to use large amounts
of CPU and memory, leading to a possible DoS vulnerability All users running
an affected release should either upgrade or use one of the workarounds
immediately.
# Workarounds
We recommend that all users upgrade to one of the FIXED versions. In the
meantime, users can mitigate this vulnerability by using a load balancer or
other device to filter out malicious If-None-Match headers before they reach
the application.
Users on Ruby 3.2.0 or greater are not affected by this vulnerability.
patched_versions:
- "~> 5.2.8"
- "~> 6.1.7, >= 6.1.7.1"
- ">= 7.0.4.1"
rubies/ruby/CVE-2022-28739.yml---
engine: ruby
cve: 2022-28739
url: https://www.ruby-lang.org/en/news/2022/04/12/buffer-overrun-in-string-to-float-cve-2022-28739/
title: Buffer overrun in String-to-Float conversion
date: 2022-04-12
description: |
A buffer-overrun vulnerability is discovered in a conversion algorithm from a
String to a Float. This vulnerability has been assigned the CVE identifier
CVE-2022-28739. We strongly recommend upgrading Ruby.
Due to a bug in an internal function that converts a String to a Float, some
conversion methods like Kernel#Float and String#to_f could cause buffer
over-read. A typical consequence is a process termination due to segmentation
fault, but in a limited circumstances, it may be exploitable for illegal
memory read.
Please update Ruby to 2.6.10, 2.7.6, 3.0.4, or 3.1.2.
patched_versions:
- ~> 2.6.10
- ~> 2.7.6
- ~> 3.0.4
- '>= 3.1.2'
gemsgem [String] (required): Name of the affected gem.library [String] (optional): Name of the ruby library which the
affected gem belongs to.framework [String] (optional): Name of the framework which the
affected gem belongs to. (e.g. rails)platform [String] (optional): If this vulnerability is platform-specific,
name of platform this vulnerability affects (e.g. jruby)cve [String] (optional): Common Vulnerabilities and Exposures (CVE) ID.osvdb [Integer] (optional): Open Sourced Vulnerability Database (OSVDB) ID.ghsa [String] (optional): GitHub Security Advisory (GHSA) ID.url [String] (required): The URL to the full advisory.title [String] (required): The title of the advisory or individual
vulnerability. It must be a single line sentence.
title: field at 80.date [Date] (required): The public disclosure date of the advisory.description [String] (required): One or more paragraphs describing the
vulnerability. It may contain multiple paragraphs.
description: | if it is more than one sentence/line.descriptions: field at 80.description: field.description: field.cvss_v2 [Float] (optional): The CVSSv2 score for the vulnerability.cvss_v3 [Float] (optional): The CVSSv3 score for the vulnerability.cvss_v4 [Float] (optional): The CVSSv4 score for the vulnerability.unaffected_versions [Array<String>] (optional): The version requirements for the
unaffected versions of the Ruby library.
unaffected_versions version ranges must be quoted (ex: ">= 1.2.3").patched_versions [Array<String>] (optional): The version requirements
for the patched versions of the Ruby library.
patched_versions version ranges must be quoted (ex: ">= 1.2.3"`).patched_versions: if you have no patched version identifiers.related [Hash<Array<String>>] (optional): Sometimes an advisory
references many urls and other identifiers. Supported keys:
cve, ghsa, osvdb, and url
cve, ghsa, and osvdb related fields are not URLs.notes [String] (optional): Internal notes regarding the vulnerability's
inclusion in this database.rubiesengine [ruby | mruby | jruby | truffleruby] (required): Name
of the affected Ruby implementation.platform [String] (optional): If this vulnerability is platform-specific,
name of platform this vulnerability affects (e.g. jruby)cve [String] (optional): Common Vulnerabilities and Exposures (CVE) ID.osvdb [Integer] (optional): Open Sourced Vulnerability Database (OSVDB) ID.ghsa [String] (optional): GitHub Security Advisory (GHSA) ID.url [String] (required): The URL to the full advisory.title [String] (required): The title of the advisory or individual
vulnerability. It must be a single line sentence.
title: field at 80.date [Date] (required): The public disclosure date of the advisory.description [String] (required): One or more paragraphs describing the
vulnerability. It may contain multiple paragraphs.
description: | (not |-) if it is more than one sentence/line.descriptions: field at 80.description: field.description: field.cvss_v2 [Float] (optional): The CVSSv2 score for the vulnerability.cvss_v3 [Float] (optional): The CVSSv3 score for the vulnerability.cvss_v4 [Float] (optional): The CVSSv4 score for the vulnerability.unaffected_versions [Array<String>] (optional): The version requirements
for the unaffected versions of the Ruby implementation.
unaffected_versions are 2 blanks from left margin.* cve, ghsa, and osvdb related fields are not URLs.patched_versions [Array<String>] (optional): The version requirements
for the patched versions of the Ruby implementation.
patched_versions/unaffected_versions version ranges must be quoted
(ex: ">= 1.2.3").patched_versionsare 2 blanks from left margin.related [Hash<Array<String>>] (optional): Sometimes an advisory
references many urls and other identifiers. Supported keys:
cve, ghsa, osvdb, and url
cve, ghsa, and osvdb related fields are not URLs.notes [String] (optional): Internal notes regarding the vulnerability's
inclusion in this database.url: field value.rspec spec/schema_validation_spec.rb for additional lint checks.Prior to submitting a pull request, run the tests:
bundle install
bundle exec rspec
Run "GH_API_TOKEN=GITHUB_TOKEN_VALUE bundle exec rake sync_github_advisories" ruby script.
Run "rake" to run the lint checks.
If new or modified advisories, submit a PR to the repo.
CAVEAT: Between steps 2 and 5, you might need to manually edit the files.
There is a script that will create initial YAML files for RubyGem advisories which are in the GitHub Security Advisory API, but are not already in this dataset. This script can be periodically run to ensure this repo has all the data that is present in the GitHub Security Advisory data.
The GitHub Security Advisory API requires a token to access it.
To run the GitHub Security Advisory sync to retrieve all advisories, start by executing the rake task:
GH_API_TOKEN="your GitHub API Token" bundle exec rake sync_github_advisories
Or, to only retrieve advisories for a single gem:
GH_API_TOKEN="your GitHub API Token" bundle exec rake sync_github_advisories[gem_name]
The maintainers of Rails LTS have asked us not to track the Rails LTS versions.
If you are using Rails LTS and bundler-audit, it is advised that you should
add the List of CVEs addressed by Rails LTS to your .bundler-audit.yml file
under ignore:.
To safeguard project security and respect our maintainers' volunteer time, a human-in-the-loop is strictly required for all submissions. While AI tools are permitted as assistants, contributors must personally review, understand, and take full responsibility for their work. Any contributions that appear to be unreviewed machine output will be closed immediately, and repeat offenders will be banned from the project and reported.
Please see CONTRIBUTORS.md.
This database also includes data from the Open Sourced Vulnerability Database developed by the Open Security Foundation (OSF) and its contributors.