Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
3446 commits
Select commit Hold shift + click to select a range
a9af5b9
Publish GHSA-xm59-rqc7-hhvf
advisory-database[bot] Feb 9, 2026
c799d06
Publish Advisories
advisory-database[bot] Feb 9, 2026
4c10f14
Publish Advisories
advisory-database[bot] Feb 9, 2026
0322056
Publish Advisories
advisory-database[bot] Feb 10, 2026
b3d42ea
Publish Advisories
advisory-database[bot] Feb 10, 2026
4b4d635
Publish Advisories
advisory-database[bot] Feb 10, 2026
3691e96
Publish Advisories
advisory-database[bot] Feb 10, 2026
c45087d
Publish Advisories
advisory-database[bot] Feb 10, 2026
145d1df
Publish Advisories
advisory-database[bot] Feb 10, 2026
5ddbab3
Publish Advisories
advisory-database[bot] Feb 10, 2026
c6a410b
Publish Advisories
advisory-database[bot] Feb 10, 2026
66f7311
Publish Advisories
advisory-database[bot] Feb 10, 2026
39eb5e9
Publish Advisories
advisory-database[bot] Feb 10, 2026
74b7dc6
Advisory Database Sync
advisory-database[bot] Feb 10, 2026
b940e9e
Publish Advisories
advisory-database[bot] Feb 10, 2026
6721978
Publish Advisories
advisory-database[bot] Feb 10, 2026
b01a5e8
Publish Advisories
advisory-database[bot] Feb 10, 2026
fa7c355
Publish Advisories
advisory-database[bot] Feb 10, 2026
db41845
Publish GHSA-68m5-5w2h-h837
advisory-database[bot] Feb 10, 2026
0b10419
Publish Advisories
advisory-database[bot] Feb 10, 2026
1ea66d4
Advisory Database Sync
advisory-database[bot] Feb 10, 2026
e80bde5
Publish Advisories
advisory-database[bot] Feb 10, 2026
03b7cc2
Publish GHSA-585q-cm62-757j
advisory-database[bot] Feb 10, 2026
b6e6397
Publish GHSA-fm6w-rrp3-2x4w
advisory-database[bot] Feb 10, 2026
ad54d69
Advisory Database Sync
advisory-database[bot] Feb 10, 2026
5b4ac8e
Publish Advisories
advisory-database[bot] Feb 10, 2026
ad09a5a
Publish Advisories
advisory-database[bot] Feb 10, 2026
f534932
Publish GHSA-6rw7-vpxm-498p
advisory-database[bot] Feb 10, 2026
669cc08
Publish GHSA-58qw-p7qm-5rvh
advisory-database[bot] Feb 10, 2026
325f95b
Publish GHSA-r6ph-v2qm-q3c2
advisory-database[bot] Feb 10, 2026
122e197
Advisory Database Sync
advisory-database[bot] Feb 10, 2026
bde0712
Publish GHSA-fpq4-r87v-g246
advisory-database[bot] Feb 10, 2026
904df3e
Publish Advisories
advisory-database[bot] Feb 11, 2026
6e8b634
Publish Advisories
advisory-database[bot] Feb 11, 2026
174ef16
Publish Advisories
advisory-database[bot] Feb 11, 2026
7dfceb4
Advisory Database Sync
advisory-database[bot] Feb 11, 2026
d18df75
Publish Advisories
advisory-database[bot] Feb 11, 2026
763aa34
Publish Advisories
advisory-database[bot] Feb 11, 2026
7cfe42b
Publish Advisories
advisory-database[bot] Feb 11, 2026
7ca85f3
Publish Advisories
advisory-database[bot] Feb 11, 2026
d8db35e
Advisory Database Sync
advisory-database[bot] Feb 11, 2026
0a388d7
Publish GHSA-gwmx-9gcj-332h
advisory-database[bot] Feb 11, 2026
01fe115
Publish GHSA-ff9r-ww9c-43x8
advisory-database[bot] Feb 11, 2026
85b1f2d
Advisory Database Sync
advisory-database[bot] Feb 11, 2026
115a304
Publish Advisories
advisory-database[bot] Feb 11, 2026
5497901
Publish Advisories
advisory-database[bot] Feb 11, 2026
5b043cc
Publish GHSA-92fh-27vv-894w
advisory-database[bot] Feb 11, 2026
8289bad
Publish Advisories
advisory-database[bot] Feb 11, 2026
2eb098a
Publish Advisories
advisory-database[bot] Feb 11, 2026
56ddc2a
Publish Advisories
advisory-database[bot] Feb 11, 2026
be30634
Publish GHSA-7ppg-37fh-vcr6
advisory-database[bot] Feb 11, 2026
b8b97a1
Advisory Database Sync
advisory-database[bot] Feb 11, 2026
ce95b17
Publish Advisories
advisory-database[bot] Feb 11, 2026
35c6994
Publish GHSA-52rh-5rpj-c3w6
advisory-database[bot] Feb 11, 2026
7b353fe
Publish GHSA-w7q7-vjp8-7jv4
advisory-database[bot] Feb 11, 2026
3311826
Publish GHSA-vmhw-fhj6-m3g5
advisory-database[bot] Feb 11, 2026
e73006a
Publish Advisories
advisory-database[bot] Feb 11, 2026
61bb77f
Publish Advisories
advisory-database[bot] Feb 11, 2026
37873db
Advisory Database Sync
advisory-database[bot] Feb 12, 2026
5f8eafb
Publish Advisories
advisory-database[bot] Feb 12, 2026
2026ca6
Publish Advisories
advisory-database[bot] Feb 12, 2026
31dbff1
Publish Advisories
advisory-database[bot] Feb 12, 2026
255476e
Publish Advisories
advisory-database[bot] Feb 12, 2026
211f2af
Publish Advisories
advisory-database[bot] Feb 12, 2026
be75420
Publish Advisories
advisory-database[bot] Feb 12, 2026
2154c99
Publish Advisories
advisory-database[bot] Feb 12, 2026
0ddf0ea
Publish Advisories
advisory-database[bot] Feb 12, 2026
3e38954
Advisory Database Sync
advisory-database[bot] Feb 12, 2026
432739c
Publish Advisories
advisory-database[bot] Feb 12, 2026
55e844c
Publish Advisories
advisory-database[bot] Feb 12, 2026
07a961c
Publish GHSA-74rh-c5rh-88vg
advisory-database[bot] Feb 12, 2026
c2e9709
Publish Advisories
advisory-database[bot] Feb 12, 2026
04cbb3f
Publish GHSA-qvhc-9v3j-5rfw
advisory-database[bot] Feb 12, 2026
b9f835e
Publish GHSA-qvhc-9v3j-5rfw
advisory-database[bot] Feb 12, 2026
51b6b93
Publish GHSA-436v-jg82-p533
advisory-database[bot] Feb 12, 2026
2f5eac8
Advisory Database Sync
advisory-database[bot] Feb 12, 2026
436b311
Publish GHSA-436v-jg82-p533
advisory-database[bot] Feb 12, 2026
dbc775f
Publish GHSA-r8w2-w357-9pjv
advisory-database[bot] Feb 12, 2026
75945b5
Publish Advisories
advisory-database[bot] Feb 12, 2026
3c99d6f
Publish Advisories
advisory-database[bot] Feb 12, 2026
4113c17
Publish GHSA-vx5f-vmr6-32wf
advisory-database[bot] Feb 12, 2026
4c646c7
Advisory Database Sync
advisory-database[bot] Feb 12, 2026
927858e
Publish Advisories
advisory-database[bot] Feb 12, 2026
9de4872
Publish Advisories
advisory-database[bot] Feb 12, 2026
8a98ba6
Publish Advisories
advisory-database[bot] Feb 12, 2026
7899f8c
Publish Advisories
advisory-database[bot] Feb 12, 2026
b14027f
Publish Advisories
advisory-database[bot] Feb 12, 2026
8a1ba06
Advisory Database Sync
advisory-database[bot] Feb 13, 2026
610ee7e
Publish Advisories
advisory-database[bot] Feb 13, 2026
aa8f165
Publish Advisories
advisory-database[bot] Feb 13, 2026
aec00c2
Publish GHSA-qvpr-vq7h-28cr
advisory-database[bot] Feb 13, 2026
515754e
Publish Advisories
advisory-database[bot] Feb 13, 2026
d7e63b2
Publish GHSA-9f3f-wv7r-qc8r
advisory-database[bot] Feb 13, 2026
e912a16
Publish GHSA-jp3q-wwp3-pwv9
advisory-database[bot] Feb 13, 2026
bc2ffab
Publish Advisories
advisory-database[bot] Feb 13, 2026
d14188d
Publish Advisories
advisory-database[bot] Feb 13, 2026
8de3c83
Publish Advisories
advisory-database[bot] Feb 13, 2026
72d2184
Publish GHSA-7ppg-37fh-vcr6
advisory-database[bot] Feb 13, 2026
fd8723f
Publish GHSA-pm44-x5x7-24c4
advisory-database[bot] Feb 13, 2026
90f4467
Advisory Database Sync
advisory-database[bot] Feb 13, 2026
7678023
Publish GHSA-qvhc-9v3j-5rfw
advisory-database[bot] Feb 13, 2026
b0da1d5
Publish GHSA-6426-9fv3-65x8
advisory-database[bot] Feb 13, 2026
acfcbcd
Publish Advisories
advisory-database[bot] Feb 13, 2026
66a9e76
Publish GHSA-wv3h-x6c4-r867
advisory-database[bot] Feb 13, 2026
111fcc8
Publish GHSA-hcvw-475w-8g7p
advisory-database[bot] Feb 13, 2026
b4e7ce4
Publish Advisories
advisory-database[bot] Feb 13, 2026
d4f4331
Publish Advisories
advisory-database[bot] Feb 13, 2026
973ada4
Publish Advisories
advisory-database[bot] Feb 13, 2026
67d3472
Publish GHSA-cgmm-x5ww-q5cr
advisory-database[bot] Feb 13, 2026
f9ac8a9
Advisory Database Sync
advisory-database[bot] Feb 13, 2026
bc3fdd2
Publish GHSA-37gf-gmxv-74wv
advisory-database[bot] Feb 13, 2026
285b9b3
Publish GHSA-g78x-7vwx-9f58
advisory-database[bot] Feb 13, 2026
1641304
Publish GHSA-699m-4v95-rmpm
advisory-database[bot] Feb 13, 2026
54b43c1
Publish GHSA-fm6w-rrp3-2x4w
advisory-database[bot] Feb 13, 2026
6076ced
Publish GHSA-78wq-6gcv-w28r
advisory-database[bot] Feb 13, 2026
5127ee6
Publish Advisories
advisory-database[bot] Feb 14, 2026
6e6e4b9
Publish GHSA-p5wr-5p37-2wm6
advisory-database[bot] Feb 14, 2026
b4cf7a0
Publish Advisories
advisory-database[bot] Feb 14, 2026
fc4eda9
Advisory Database Sync
advisory-database[bot] Feb 14, 2026
b7ec4ee
Publish Advisories
advisory-database[bot] Feb 14, 2026
99426e3
Publish Advisories
advisory-database[bot] Feb 14, 2026
3244613
Advisory Database Sync
advisory-database[bot] Feb 14, 2026
2a4bb68
Publish Advisories
advisory-database[bot] Feb 15, 2026
e5296e2
Publish Advisories
advisory-database[bot] Feb 15, 2026
fb52933
Publish Advisories
advisory-database[bot] Feb 15, 2026
9580c22
Publish Advisories
advisory-database[bot] Feb 15, 2026
064f966
Publish Advisories
advisory-database[bot] Feb 16, 2026
d0a5254
Publish Advisories
advisory-database[bot] Feb 16, 2026
8b7564a
Publish Advisories
advisory-database[bot] Feb 16, 2026
3e1bb70
Publish Advisories
advisory-database[bot] Feb 16, 2026
aa91897
Publish Advisories
advisory-database[bot] Feb 16, 2026
eb17559
Publish Advisories
advisory-database[bot] Feb 16, 2026
9a40eb1
Advisory Database Sync
advisory-database[bot] Feb 16, 2026
41d956f
Publish Advisories
advisory-database[bot] Feb 16, 2026
e1df577
Publish Advisories
advisory-database[bot] Feb 17, 2026
f0d3f11
Publish Advisories
advisory-database[bot] Feb 17, 2026
2d2b81c
Publish Advisories
advisory-database[bot] Feb 17, 2026
f981753
Publish Advisories
advisory-database[bot] Feb 17, 2026
e4a343d
Publish Advisories
advisory-database[bot] Feb 17, 2026
f3339c0
Advisory Database Sync
advisory-database[bot] Feb 17, 2026
4fb15b5
Publish GHSA-x4c5-c7rf-jjgv
advisory-database[bot] Feb 17, 2026
a13e2ae
Publish Advisories
advisory-database[bot] Feb 17, 2026
fab046e
Publish Advisories
advisory-database[bot] Feb 17, 2026
535ca43
Publish Advisories
advisory-database[bot] Feb 17, 2026
8ae550c
Publish Advisories
advisory-database[bot] Feb 17, 2026
b1d7234
Publish Advisories
advisory-database[bot] Feb 17, 2026
0fc4c48
Publish GHSA-qw99-grcx-4pvm
advisory-database[bot] Feb 17, 2026
2169cb9
Publish Advisories
advisory-database[bot] Feb 17, 2026
2b4272d
Publish GHSA-hr7j-63v7-vj7g
advisory-database[bot] Feb 17, 2026
b45febd
Publish GHSA-64w3-5q9m-68xf
advisory-database[bot] Feb 17, 2026
a08849d
Publish GHSA-895x-rfqp-jh5c
advisory-database[bot] Feb 17, 2026
021d64b
Publish GHSA-4hx9-48xh-5mxr
advisory-database[bot] Feb 17, 2026
b028746
Publish GHSA-2g4f-4pwh-qvx6
advisory-database[bot] Feb 17, 2026
694d5e1
Advisory Database Sync
advisory-database[bot] Feb 17, 2026
abab9e9
Publish Advisories
advisory-database[bot] Feb 17, 2026
8bee4b5
Publish Advisories
advisory-database[bot] Feb 17, 2026
57363d6
Publish GHSA-fc3h-92p8-h36f
advisory-database[bot] Feb 17, 2026
46de19c
Publish Advisories
advisory-database[bot] Feb 17, 2026
fbb3692
Publish Advisories
advisory-database[bot] Feb 17, 2026
c21fb3b
Publish GHSA-ppfx-73j5-fhxc
advisory-database[bot] Feb 17, 2026
aef70ae
Publish GHSA-x4gp-pqpj-f43q
advisory-database[bot] Feb 17, 2026
5f78d37
Publish Advisories
advisory-database[bot] Feb 17, 2026
49ecfb1
Publish Advisories
advisory-database[bot] Feb 17, 2026
f835ce7
Publish Advisories
advisory-database[bot] Feb 17, 2026
42ec163
Advisory Database Sync
advisory-database[bot] Feb 17, 2026
cc1f14b
Publish Advisories
advisory-database[bot] Feb 17, 2026
d0c143e
Publish Advisories
advisory-database[bot] Feb 17, 2026
5e80a62
Publish Advisories
advisory-database[bot] Feb 17, 2026
6234aea
Publish GHSA-87r5-mp6g-5w5j
advisory-database[bot] Feb 17, 2026
d50ee2b
Publish GHSA-pjwm-rvh2-c87w
advisory-database[bot] Feb 17, 2026
18bef7e
Publish Advisories
advisory-database[bot] Feb 17, 2026
6b0d1aa
Publish Advisories
advisory-database[bot] Feb 17, 2026
2d536ff
Publish GHSA-chm2-m3w2-wcxm
advisory-database[bot] Feb 17, 2026
cf66382
Publish Advisories
advisory-database[bot] Feb 18, 2026
a0993d7
Publish GHSA-pv58-549p-qh99
advisory-database[bot] Feb 18, 2026
d3a1d62
Publish GHSA-g34w-4xqq-h79m
advisory-database[bot] Feb 18, 2026
4728411
Publish Advisories
advisory-database[bot] Feb 18, 2026
acf99cc
Publish Advisories
advisory-database[bot] Feb 18, 2026
676a0da
Publish Advisories
advisory-database[bot] Feb 18, 2026
4c83c82
Publish Advisories
advisory-database[bot] Feb 18, 2026
7203f64
Advisory Database Sync
advisory-database[bot] Feb 18, 2026
d6d6c97
Publish Advisories
advisory-database[bot] Feb 18, 2026
624ae4c
Publish Advisories
advisory-database[bot] Feb 18, 2026
0be8ae2
Improve GHSA-xfhx-r7ww-5995
maksim-m Feb 18, 2026
4ef3aa1
Publish Advisories
advisory-database[bot] Feb 18, 2026
0a0ba0f
Advisory Database Sync
advisory-database[bot] Feb 18, 2026
a70887b
Merge pull request #6956 from github/maksim-m-GHSA-xfhx-r7ww-5995
advisory-database[bot] Feb 18, 2026
5c0e07c
Publish GHSA-xfhx-r7ww-5995
advisory-database[bot] Feb 18, 2026
2e5cf78
Publish GHSA-43fc-jf86-j433
advisory-database[bot] Feb 18, 2026
0bb5d2b
Publish Advisories
advisory-database[bot] Feb 18, 2026
0083c7c
Publish Advisories
advisory-database[bot] Feb 18, 2026
175bf9c
Publish GHSA-jfv4-h8mc-jcp8
advisory-database[bot] Feb 18, 2026
600a0a3
Publish Advisories
advisory-database[bot] Feb 18, 2026
51aad82
Publish GHSA-6xw9-2p64-7622
advisory-database[bot] Feb 18, 2026
5b7321c
Advisory Database Sync
advisory-database[bot] Feb 18, 2026
67ec8ed
Advisory Database Sync
advisory-database[bot] Feb 18, 2026
c7b29b3
Publish Advisories
advisory-database[bot] Feb 18, 2026
c14bf0f
Publish Advisories
advisory-database[bot] Feb 18, 2026
2f7e08e
Publish GHSA-wx95-c6cv-8532
advisory-database[bot] Feb 18, 2026
41148b5
Publish Advisories
advisory-database[bot] Feb 18, 2026
b79537e
Publish Advisories
advisory-database[bot] Feb 18, 2026
81336c8
Publish Advisories
advisory-database[bot] Feb 18, 2026
799717c
Publish Advisories
advisory-database[bot] Feb 18, 2026
aa4d96d
Publish Advisories
advisory-database[bot] Feb 18, 2026
fe8107c
Publish Advisories
advisory-database[bot] Feb 18, 2026
44697e2
Publish Advisories
advisory-database[bot] Feb 18, 2026
f462145
Publish Advisories
advisory-database[bot] Feb 18, 2026
538d183
Publish Advisories
advisory-database[bot] Feb 18, 2026
32a17ae
Publish GHSA-pqqf-7hxm-rj5r
advisory-database[bot] Feb 18, 2026
089089d
Publish GHSA-2ww3-72rp-wpp4
advisory-database[bot] Feb 18, 2026
488a79e
Publish Advisories
advisory-database[bot] Feb 18, 2026
450add9
Publish Advisories
advisory-database[bot] Feb 18, 2026
0874b56
Publish Advisories
advisory-database[bot] Feb 18, 2026
76ad3dc
Publish Advisories
advisory-database[bot] Feb 18, 2026
9279da8
Publish Advisories
advisory-database[bot] Feb 18, 2026
6ea42f1
Advisory Database Sync
advisory-database[bot] Feb 19, 2026
618fadc
Publish Advisories
advisory-database[bot] Feb 19, 2026
ead68b2
Publish Advisories
advisory-database[bot] Feb 19, 2026
465ccbb
Publish Advisories
advisory-database[bot] Feb 19, 2026
33f1945
Publish Advisories
advisory-database[bot] Feb 19, 2026
20d53d5
Advisory Database Sync
advisory-database[bot] Feb 19, 2026
0de16c6
Advisory Database Sync
advisory-database[bot] Feb 19, 2026
3b3e802
Publish GHSA-9f29-v6mm-pw6w
advisory-database[bot] Feb 19, 2026
78f91be
Publish Advisories
advisory-database[bot] Feb 19, 2026
58c895b
Publish Advisories
advisory-database[bot] Feb 19, 2026
2649f9d
Publish Advisories
advisory-database[bot] Feb 19, 2026
de9540d
Publish Advisories
advisory-database[bot] Feb 19, 2026
2869df6
Publish GHSA-gq3j-xvxp-8hrf
advisory-database[bot] Feb 19, 2026
56cbd5f
Publish Advisories
advisory-database[bot] Feb 19, 2026
cc944bc
Publish Advisories
advisory-database[bot] Feb 19, 2026
bbedc4f
Publish Advisories
advisory-database[bot] Feb 19, 2026
8290b32
Publish Advisories
advisory-database[bot] Feb 19, 2026
a57d901
Publish Advisories
advisory-database[bot] Feb 19, 2026
d1b99fb
Publish GHSA-67pg-wm7f-q7fj
advisory-database[bot] Feb 19, 2026
24430b5
Publish GHSA-2xcx-75h9-vr9h
advisory-database[bot] Feb 19, 2026
1ac0f74
Publish Advisories
advisory-database[bot] Feb 19, 2026
760bb6b
Publish Advisories
advisory-database[bot] Feb 19, 2026
8b065cc
Advisory Database Sync
advisory-database[bot] Feb 19, 2026
2f05351
Publish Advisories
advisory-database[bot] Feb 19, 2026
e5f2c22
Publish GHSA-fwxx-wv44-7qfg
advisory-database[bot] Feb 19, 2026
6b2fe29
Publish Advisories
advisory-database[bot] Feb 19, 2026
cc905f2
Publish Advisories
advisory-database[bot] Feb 19, 2026
38f4067
Publish Advisories
advisory-database[bot] Feb 19, 2026
ae16c8d
Publish Advisories
advisory-database[bot] Feb 19, 2026
fbdb304
Publish GHSA-pv58-549p-qh99
advisory-database[bot] Feb 19, 2026
2a4cc40
Advisory Database Sync
advisory-database[bot] Feb 20, 2026
03399a2
Publish Advisories
advisory-database[bot] Feb 20, 2026
8b38a69
Publish Advisories
advisory-database[bot] Feb 20, 2026
86b2861
Publish Advisories
advisory-database[bot] Feb 20, 2026
7b0594e
Publish Advisories
advisory-database[bot] Feb 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
4 changes: 4 additions & 0 deletions .github/workflows/create_staging_branch.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ on:
- "advisories/**"
workflow_dispatch:

permissions:
contents: write # Required to create and push branches
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Variable files

pull-requests: write # Required to edit PR base branch

jobs:
ensure-base-is-staging:
runs-on: ubuntu-latest
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/delete_staging_and_head_branches.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ on:
- "advisories/**"
workflow_dispatch:

permissions:
contents: write # Required to delete branches

jobs:
delete-staging-and-head-branches:
if: ${{ !github.event.pull_request.head.repo.fork }}
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/stale.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
schedule:
- cron: "00 0 * * *" # runs at 00:00 daily

permissions:
pull-requests: write # Required to comment on, label, and close PRs

jobs:
stale:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4whc-pp4x-9pf3",
"modified": "2023-01-20T22:28:49Z",
"modified": "2026-01-14T21:44:14Z",
"published": "2017-10-24T18:33:36Z",
"aliases": [
"CVE-2015-1840"
Expand Down Expand Up @@ -89,6 +89,10 @@
"type": "WEB",
"url": "https://github.com/rails/jquery-ujs/blob/master/CHANGELOG.md"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2015-1840.yml"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-ujs/CVE-2015-1840.yml"
Expand Down Expand Up @@ -129,6 +133,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T20:59:28Z",
"nvd_published_at": null
"nvd_published_at": "2015-07-26T22:59:00Z"
}
}
Original file line number Diff line number Diff line change
@@ -1,14 +1,19 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6x85-j5j2-27jx",
"modified": "2023-02-15T22:22:18Z",
"modified": "2025-10-24T19:28:04Z",
"published": "2017-10-24T18:33:36Z",
"aliases": [
"CVE-2014-0130"
],
"summary": "actionpack Path Traversal vulnerability",
"details": "Directory traversal vulnerability in `actionpack/lib/abstract_controller/base.rb` in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H"
}
],
"affected": [
{
"package": {
Expand Down Expand Up @@ -101,6 +106,10 @@
"type": "WEB",
"url": "https://groups.google.com/forum/#!topic/rubyonrails-security/NkKc7vTW70o"
},
{
"type": "WEB",
"url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/NkKc7vTW70o/NxW_PDBSG3AJ"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20140518192004/http://www.securityfocus.com/bid/67244"
Expand All @@ -113,6 +122,14 @@
"type": "WEB",
"url": "https://web.archive.org/web/20210411041816/https://groups.google.com/forum/message/raw?msg=rubyonrails-security/NkKc7vTW70o/NxW_PDBSG3AJ"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0130"
},
{
"type": "WEB",
"url": "http://matasano.com/research/AnatomyOfRailsVuln-CVE-2014-0130.pdf"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2014-1863.html"
Expand All @@ -122,7 +139,7 @@
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:20:36Z",
"nvd_published_at": "2014-05-07T10:55:00Z"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f522-ffg8-j8r6",
"modified": "2024-10-02T17:16:12Z",
"modified": "2025-10-17T17:50:27Z",
"published": "2017-10-24T18:33:35Z",
"aliases": [
"CVE-2016-2537"
],
"summary": "Regular Expression Denial of Service in is-my-json-valid",
"details": "Version of `is-my-json-valid` before 1.4.1 or 2.17.2 are vulnerable to regular expression denial of service (ReDoS) via the email validation function.\n\n\n## Recommendation\n\nUpdate to version 1.4.1, 2.17.2 or later.",
"details": "Version of `is-my-json-valid` before 2.12.4 are vulnerable to regular expression denial of service (ReDoS) via the email validation function.\n\n\n## Recommendation\n\nUpdate to version 2.12.4 or later.",
"severity": [
{
"type": "CVSS_V3",
Expand All @@ -28,7 +28,7 @@
"introduced": "0"
},
{
"fixed": "2.17.2"
"fixed": "2.12.4"
}
]
}
Expand Down Expand Up @@ -84,6 +84,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:33:36Z",
"nvd_published_at": null
"nvd_published_at": "2016-02-23T05:59:01Z"
}
}
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6w6-xmqv-7q78",
"modified": "2023-05-12T17:14:49Z",
"modified": "2025-11-03T13:56:05Z",
"published": "2017-10-24T18:33:38Z",
"aliases": [
"CVE-2011-2930"
Expand Down Expand Up @@ -39,14 +39,33 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
"introduced": "3.0.0.beta"
},
{
"fixed": "3.0.10"
}
]
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "activerecord"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.1.0.beta1"
},
{
"fixed": "3.1.0.rc5"
}
]
}
]
}
],
"references": [
Expand Down
Original file line number Diff line number Diff line change
@@ -1,37 +1,15 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxvp-4xwc-jpp6",
"modified": "2023-01-23T18:04:55Z",
"modified": "2025-11-04T20:42:18Z",
"published": "2017-10-24T18:33:36Z",
"aliases": [
"CVE-2015-3226"
],
"summary": "activesupport Cross-site Scripting vulnerability",
"details": "Cross-site scripting (XSS) vulnerability in `json/encoding.rb` in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.",
"details": "Cross-site scripting (XSS) vulnerability in `json/encoding.rb` in Active Support in Ruby on Rails 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.",
"severity": [],
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "activesupport"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.2.22.5"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 3.2.22.4"
}
},
{
"package": {
"ecosystem": "RubyGems",
Expand Down Expand Up @@ -76,10 +54,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-3226"
},
{
"type": "PACKAGE",
"url": "https://github.com/rails/rails"
},
{
"type": "WEB",
"url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/7VlB_pck3hU/3QZrGIaQW6cJ"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/rubyonrails-core/c/qBUqVlXERag/m/kuH3wQk1kxUJ"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200228033946/http://www.securityfocus.com/bid/75231"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xrr4-p6fq-hjg7",
"modified": "2024-07-16T20:12:47Z",
"modified": "2025-10-22T17:35:03Z",
"published": "2017-10-24T18:33:35Z",
"aliases": [
"CVE-2016-0752"
Expand All @@ -11,7 +11,7 @@
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H"
}
],
"affected": [
Expand Down Expand Up @@ -160,6 +160,10 @@
"type": "WEB",
"url": "https://web.archive.org/web/20210723192420/http://www.securitytracker.com/id/1034816"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0752"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/40561"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv4c-p2j5-38j4",
"modified": "2023-09-11T22:06:04Z",
"modified": "2026-01-23T20:10:56Z",
"published": "2018-08-13T15:02:15Z",
"aliases": [
"CVE-2018-3774"
Expand All @@ -25,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
"introduced": "1.0.0"
},
{
"fixed": "1.4.3"
Expand All @@ -40,6 +40,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-3774"
},
{
"type": "WEB",
"url": "https://github.com/unshiftio/url-parse/commit/209c296d302317268afbe19700a70c63ecbeb2d2"
},
{
"type": "WEB",
"url": "https://github.com/unshiftio/url-parse/commit/53b1794e54d0711ceb52505e0f74145270570d5a"
Expand All @@ -53,12 +57,12 @@
"url": "https://hackerone.com/reports/384029"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-pv4c-p2j5-38j4"
"type": "PACKAGE",
"url": "https://github.com/unshiftio/url-parse"
},
{
"type": "WEB",
"url": "https://www.npmjs.com/advisories/678"
"url": "https://github.com/unshiftio/url-parse/compare/0.2.3...1.0.0"
}
],
"database_specific": {
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pj7m-g53m-7638",
"modified": "2024-08-01T21:03:38Z",
"modified": "2025-11-19T14:25:32Z",
"published": "2018-09-13T15:49:56Z",
"aliases": [
"CVE-2018-14041"
Expand Down Expand Up @@ -259,6 +259,10 @@
"type": "PACKAGE",
"url": "https://github.com/twbs/bootstrap"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap/CVE-2018-14041.yml"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2018-14041.yaml"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xq8-pvg4-3mf3",
"modified": "2022-09-14T19:17:28Z",
"modified": "2025-10-15T16:43:16Z",
"published": "2018-10-19T16:54:11Z",
"aliases": [
"CVE-2018-1000644"
],
"summary": "Eclipse RDF4j vulnerable to XML External Entitiy",
"summary": "Eclipse RDF4j vulnerable to XML External Entity",
"details": "Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.",
"severity": [
{
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr6j-3jp9-rw65",
"modified": "2024-07-25T20:16:22Z",
"modified": "2025-10-22T17:29:40Z",
"published": "2018-10-18T19:24:38Z",
"aliases": [
"CVE-2018-11776"
Expand All @@ -11,7 +11,7 @@
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H"
}
],
"affected": [
Expand Down Expand Up @@ -89,6 +89,10 @@
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/45260"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20201208145803/https://securitytracker.com/id/1041547"
Expand Down
Loading
Loading