Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
789 commits
Select commit Hold shift + click to select a range
6737202
Publish GHSA-9342-92gg-6v29
advisory-database[bot] Apr 16, 2026
08a616f
Publish Advisories
advisory-database[bot] Apr 16, 2026
37f24b3
Publish GHSA-37gx-xxp4-5rgx
advisory-database[bot] Apr 16, 2026
bfe5818
Publish Advisories
advisory-database[bot] Apr 16, 2026
6ada108
Publish Advisories
advisory-database[bot] Apr 16, 2026
cd8085d
Publish Advisories
advisory-database[bot] Apr 16, 2026
87ee3cd
Publish Advisories
advisory-database[bot] Apr 16, 2026
4c982a9
Publish Advisories
advisory-database[bot] Apr 16, 2026
d8eb64e
Publish Advisories
advisory-database[bot] Apr 16, 2026
a5f0517
Publish Advisories
advisory-database[bot] Apr 16, 2026
8af2ed4
Publish Advisories
advisory-database[bot] Apr 16, 2026
9232845
Publish Advisories
advisory-database[bot] Apr 16, 2026
d17ccea
Publish Advisories
advisory-database[bot] Apr 16, 2026
d0efe19
Publish Advisories
advisory-database[bot] Apr 16, 2026
27a53ed
Advisory Database Sync
advisory-database[bot] Apr 16, 2026
a0d52b4
Publish Advisories
advisory-database[bot] Apr 16, 2026
4fd7aed
Publish Advisories
advisory-database[bot] Apr 16, 2026
a9c9466
Publish Advisories
advisory-database[bot] Apr 16, 2026
add3963
Publish Advisories
advisory-database[bot] Apr 16, 2026
bcf3b02
Publish Advisories
advisory-database[bot] Apr 16, 2026
179397f
Publish Advisories
advisory-database[bot] Apr 16, 2026
2469dc1
Publish Advisories
advisory-database[bot] Apr 16, 2026
7ca3aba
Publish Advisories
advisory-database[bot] Apr 16, 2026
a716398
Publish Advisories
advisory-database[bot] Apr 16, 2026
5c51f61
Publish Advisories
advisory-database[bot] Apr 16, 2026
23f2ec9
Publish Advisories
advisory-database[bot] Apr 16, 2026
36344dd
Publish Advisories
advisory-database[bot] Apr 16, 2026
047dff8
Publish Advisories
advisory-database[bot] Apr 16, 2026
811cb51
Publish Advisories
advisory-database[bot] Apr 16, 2026
03b51b8
Publish Advisories
advisory-database[bot] Apr 16, 2026
7c26e64
Publish Advisories
advisory-database[bot] Apr 16, 2026
6789b76
Publish Advisories
advisory-database[bot] Apr 16, 2026
389034b
Publish Advisories
advisory-database[bot] Apr 16, 2026
2b57769
Publish Advisories
advisory-database[bot] Apr 16, 2026
e669840
Publish Advisories
advisory-database[bot] Apr 16, 2026
1aa536c
Publish Advisories
advisory-database[bot] Apr 17, 2026
e1ea192
Publish Advisories
advisory-database[bot] Apr 17, 2026
209a600
Publish Advisories
advisory-database[bot] Apr 17, 2026
f698c09
Publish Advisories
advisory-database[bot] Apr 17, 2026
331a711
Publish Advisories
advisory-database[bot] Apr 17, 2026
867d014
Publish Advisories
advisory-database[bot] Apr 17, 2026
a2af9c1
Publish Advisories
advisory-database[bot] Apr 17, 2026
c553edb
Publish GHSA-6r5v-hp32-fjqw
advisory-database[bot] Apr 17, 2026
a998b93
Advisory Database Sync
advisory-database[bot] Apr 17, 2026
2f09d5e
Advisory Database Sync
advisory-database[bot] Apr 17, 2026
32fc5cf
Publish GHSA-6wpv-cj6x-v3jw
advisory-database[bot] Apr 17, 2026
f65ba00
Publish GHSA-92jp-89mq-4374
advisory-database[bot] Apr 17, 2026
bef1095
Publish Advisories
advisory-database[bot] Apr 17, 2026
6207326
Publish Advisories
advisory-database[bot] Apr 17, 2026
8a379c5
Publish Advisories
advisory-database[bot] Apr 17, 2026
1c7732a
Publish GHSA-jwrq-8g5x-5fhm
advisory-database[bot] Apr 17, 2026
66cf483
Publish Advisories
advisory-database[bot] Apr 17, 2026
284d48b
Publish Advisories
advisory-database[bot] Apr 17, 2026
a46d26e
Publish Advisories
advisory-database[bot] Apr 17, 2026
0510052
Publish Advisories
advisory-database[bot] Apr 17, 2026
23e68d2
Publish Advisories
advisory-database[bot] Apr 17, 2026
ad3d100
Publish Advisories
advisory-database[bot] Apr 17, 2026
9142cfe
Publish Advisories
advisory-database[bot] Apr 17, 2026
b2cbf1a
Publish Advisories
advisory-database[bot] Apr 17, 2026
200643c
Publish Advisories
advisory-database[bot] Apr 17, 2026
acc7e18
Publish Advisories
advisory-database[bot] Apr 17, 2026
7c6a40e
Publish Advisories
advisory-database[bot] Apr 17, 2026
a469af6
Publish Advisories
advisory-database[bot] Apr 17, 2026
110e17b
Publish Advisories
advisory-database[bot] Apr 17, 2026
cf23f30
Publish Advisories
advisory-database[bot] Apr 17, 2026
79599f5
Publish GHSA-63x8-x938-vx33
advisory-database[bot] Apr 17, 2026
d96dd1b
Publish GHSA-2x8m-83vc-6wv4
advisory-database[bot] Apr 18, 2026
ab8621e
Publish GHSA-xgrm-4fwx-7qm8
advisory-database[bot] Apr 18, 2026
bc4fc9c
Publish Advisories
advisory-database[bot] Apr 18, 2026
a4633df
Publish Advisories
advisory-database[bot] Apr 18, 2026
ff23dc9
Publish Advisories
advisory-database[bot] Apr 18, 2026
a8de38b
Publish Advisories
advisory-database[bot] Apr 18, 2026
1658312
Publish Advisories
advisory-database[bot] Apr 18, 2026
ac3f426
Publish Advisories
advisory-database[bot] Apr 18, 2026
74a2288
Publish Advisories
advisory-database[bot] Apr 18, 2026
86d9add
Publish Advisories
advisory-database[bot] Apr 18, 2026
76ada79
Publish Advisories
advisory-database[bot] Apr 18, 2026
d855392
Publish Advisories
advisory-database[bot] Apr 18, 2026
b07a832
Publish Advisories
advisory-database[bot] Apr 18, 2026
2dba571
Publish Advisories
advisory-database[bot] Apr 18, 2026
4f060b0
Publish GHSA-xjvp-7243-rg9h
advisory-database[bot] Apr 18, 2026
aef5bed
Publish Advisories
advisory-database[bot] Apr 18, 2026
0dd7696
Publish Advisories
advisory-database[bot] Apr 18, 2026
baaacf3
Publish Advisories
advisory-database[bot] Apr 18, 2026
14964a3
Publish Advisories
advisory-database[bot] Apr 18, 2026
f2eee93
Advisory Database Sync
advisory-database[bot] Apr 18, 2026
2b381a3
Publish Advisories
advisory-database[bot] Apr 18, 2026
a22a9f3
Publish Advisories
advisory-database[bot] Apr 18, 2026
910f444
Publish GHSA-xq3m-2v4x-88gg
advisory-database[bot] Apr 18, 2026
78fcc3b
Publish GHSA-j23v-33r7-63rx
advisory-database[bot] Apr 18, 2026
79a89ee
Publish GHSA-gwjg-rpxc-39ph
advisory-database[bot] Apr 19, 2026
23e8964
Publish Advisories
advisory-database[bot] Apr 19, 2026
cf6d960
Publish Advisories
advisory-database[bot] Apr 19, 2026
89a1ac0
Publish Advisories
advisory-database[bot] Apr 19, 2026
6628e9b
Publish Advisories
advisory-database[bot] Apr 19, 2026
0bcffbc
Publish Advisories
advisory-database[bot] Apr 19, 2026
74511a0
Publish Advisories
advisory-database[bot] Apr 20, 2026
d92007d
Publish Advisories
advisory-database[bot] Apr 20, 2026
9ca9084
Advisory Database Sync
advisory-database[bot] Apr 20, 2026
698cd61
Publish Advisories
advisory-database[bot] Apr 20, 2026
45e5fa7
Publish Advisories
advisory-database[bot] Apr 20, 2026
24fa3cc
Advisory Database Sync
advisory-database[bot] Apr 20, 2026
cd940f9
Advisory Database Sync
advisory-database[bot] Apr 20, 2026
161692f
Publish GHSA-qrr6-mg7r-m243
advisory-database[bot] Apr 20, 2026
5e6582e
Advisory Database Sync
advisory-database[bot] Apr 20, 2026
8ea22aa
Publish Advisories
advisory-database[bot] Apr 20, 2026
dbfe3b8
Publish Advisories
advisory-database[bot] Apr 20, 2026
5e2beba
Publish Advisories
advisory-database[bot] Apr 21, 2026
9e505fb
Publish Advisories
advisory-database[bot] Apr 21, 2026
a38472a
Publish Advisories
advisory-database[bot] Apr 21, 2026
8356d8b
Publish Advisories
advisory-database[bot] Apr 21, 2026
06ed819
Publish GHSA-gg73-7cr3-89ff
advisory-database[bot] Apr 21, 2026
64c9b16
Publish Advisories
advisory-database[bot] Apr 21, 2026
21a6732
Publish Advisories
advisory-database[bot] Apr 21, 2026
9c345da
Publish GHSA-fg79-cr9c-7369
advisory-database[bot] Apr 21, 2026
9903d79
Publish GHSA-6vqf-6fhm-7rc6
advisory-database[bot] Apr 21, 2026
1527342
Publish GHSA-mf9w-mj56-hr94
advisory-database[bot] Apr 21, 2026
a113a79
Publish GHSA-x3j7-7pgj-h87r
advisory-database[bot] Apr 21, 2026
f54af43
Publish GHSA-69rw-45wj-g4v6
advisory-database[bot] Apr 21, 2026
85069cd
Publish GHSA-x234-x5vq-cc2v
advisory-database[bot] Apr 21, 2026
7961344
Publish GHSA-6w67-hwm5-92mq
advisory-database[bot] Apr 21, 2026
29e9514
Publish GHSA-78mf-482w-62qj
advisory-database[bot] Apr 21, 2026
0104366
Publish Advisories
advisory-database[bot] Apr 21, 2026
b224c40
Publish Advisories
advisory-database[bot] Apr 21, 2026
807a46c
Publish Advisories
advisory-database[bot] Apr 21, 2026
a495410
Advisory Database Sync
advisory-database[bot] Apr 21, 2026
66301f9
Publish GHSA-rmx9-2pp3-xhcr
advisory-database[bot] Apr 21, 2026
a1b7bf0
Publish Advisories
advisory-database[bot] Apr 21, 2026
b625304
Publish Advisories
advisory-database[bot] Apr 21, 2026
9dfd16a
Publish Advisories
advisory-database[bot] Apr 21, 2026
ebbfa33
Publish Advisories
advisory-database[bot] Apr 21, 2026
766f527
Publish GHSA-r65v-xgwc-g56j
advisory-database[bot] Apr 21, 2026
6279934
Publish Advisories
advisory-database[bot] Apr 21, 2026
673c727
Advisory Database Sync
advisory-database[bot] Apr 21, 2026
ea777bf
Publish Advisories
advisory-database[bot] Apr 21, 2026
cc2ab7c
Publish GHSA-3j5q-7q7h-2hhv
advisory-database[bot] Apr 21, 2026
0b3d77d
Publish GHSA-jwch-w7wh-gqjm
advisory-database[bot] Apr 21, 2026
47fc9ef
Publish GHSA-jj7c-x25r-r8r3
advisory-database[bot] Apr 21, 2026
b75c23a
Publish GHSA-3hjv-c53m-58jj
advisory-database[bot] Apr 21, 2026
7b976f0
Publish Advisories
advisory-database[bot] Apr 21, 2026
e6f0c19
Publish GHSA-94jr-7pqp-xhcq
advisory-database[bot] Apr 21, 2026
e34b71f
Publish Advisories
advisory-database[bot] Apr 21, 2026
1d7a5bf
Advisory Database Sync
advisory-database[bot] Apr 21, 2026
c09a1ff
Publish GHSA-6ffj-2wg2-w45j
advisory-database[bot] Apr 21, 2026
1209e43
Advisory Database Sync
advisory-database[bot] Apr 22, 2026
1f36db8
Publish Advisories
advisory-database[bot] Apr 22, 2026
22abbb5
Publish Advisories
advisory-database[bot] Apr 22, 2026
decfb4c
Advisory Database Sync
advisory-database[bot] Apr 22, 2026
f5409f0
Publish Advisories
advisory-database[bot] Apr 22, 2026
17dff30
Publish GHSA-246w-jgmq-88fg
advisory-database[bot] Apr 22, 2026
9234cf1
Publish GHSA-9237-rg5p-rhfw
advisory-database[bot] Apr 22, 2026
d7e07ba
Publish GHSA-73h3-mf4w-8647
advisory-database[bot] Apr 22, 2026
169b342
Publish Advisories
advisory-database[bot] Apr 22, 2026
6f47dc5
Publish Advisories
advisory-database[bot] Apr 22, 2026
3610a1b
Publish GHSA-2r2p-4cgf-hv7h
advisory-database[bot] Apr 22, 2026
dc08d2d
Publish GHSA-mh6w-vxff-9wqp
advisory-database[bot] Apr 22, 2026
9127ecf
Advisory Database Sync
advisory-database[bot] Apr 22, 2026
f216263
Publish GHSA-4hfh-fch3-5q7p
advisory-database[bot] Apr 22, 2026
bcc39a6
Publish GHSA-w7cf-2pmc-5m4c
advisory-database[bot] Apr 22, 2026
50ee487
Publish Advisories
advisory-database[bot] Apr 22, 2026
22244f8
Publish Advisories
advisory-database[bot] Apr 22, 2026
5ba0c1b
Publish Advisories
advisory-database[bot] Apr 22, 2026
6644dfa
Publish Advisories
advisory-database[bot] Apr 22, 2026
95583cf
Publish Advisories
advisory-database[bot] Apr 22, 2026
c3aba5c
Publish Advisories
advisory-database[bot] Apr 22, 2026
52d1a65
Publish GHSA-79qw-g77v-2vfh
advisory-database[bot] Apr 22, 2026
a3f6c5e
Advisory Database Sync
advisory-database[bot] Apr 22, 2026
80dbbc6
Publish GHSA-34r5-6j7w-235f
advisory-database[bot] Apr 22, 2026
3af9295
Publish GHSA-x2xq-qhjf-5mvg
advisory-database[bot] Apr 22, 2026
7c3258e
Publish GHSA-6973-8887-87ff
advisory-database[bot] Apr 22, 2026
085cf3f
Publish Advisories
advisory-database[bot] Apr 22, 2026
241d3f9
Publish Advisories
advisory-database[bot] Apr 22, 2026
d34d3eb
Publish Advisories
advisory-database[bot] Apr 22, 2026
bb3e540
Publish GHSA-57j5-qwp2-vqp6
advisory-database[bot] Apr 22, 2026
af25494
Publish GHSA-98cp-84m9-q3qp
advisory-database[bot] Apr 22, 2026
d8ae83d
Publish Advisories
advisory-database[bot] Apr 22, 2026
c595890
Publish Advisories
advisory-database[bot] Apr 22, 2026
b95d43e
Publish GHSA-gh4j-gqv2-49f6
advisory-database[bot] Apr 22, 2026
c66097a
Publish GHSA-wrwh-c28m-9jjh
advisory-database[bot] Apr 22, 2026
1d51e2a
Publish GHSA-4948-f92q-f432
advisory-database[bot] Apr 22, 2026
7250054
Publish GHSA-cq8v-f236-94qc
advisory-database[bot] Apr 22, 2026
bc710f4
Publish Advisories
advisory-database[bot] Apr 22, 2026
69e3306
Publish GHSA-f6ww-3ggp-fr8h
advisory-database[bot] Apr 22, 2026
3ff2fce
Publish GHSA-2v35-w6hq-6mfw
advisory-database[bot] Apr 22, 2026
48ed9a4
Publish Advisories
advisory-database[bot] Apr 22, 2026
901f1e4
Publish GHSA-w937-fg2h-xhq2
advisory-database[bot] Apr 22, 2026
2f2e35a
Publish Advisories
advisory-database[bot] Apr 22, 2026
7af1529
Publish GHSA-j88v-2chj-qfwx
advisory-database[bot] Apr 22, 2026
6e9c51e
Publish Advisories
advisory-database[bot] Apr 22, 2026
d299da6
Publish GHSA-w5hq-g745-h8pq
advisory-database[bot] Apr 22, 2026
7548721
Publish GHSA-hppc-g8h3-xhp3
advisory-database[bot] Apr 22, 2026
bc64e62
Publish GHSA-ghm9-cr32-g9qj
advisory-database[bot] Apr 22, 2026
84b91e1
Publish GHSA-8c75-8mhr-p7r9
advisory-database[bot] Apr 22, 2026
3b0c02a
Publish Advisories
advisory-database[bot] Apr 22, 2026
463bf21
Publish GHSA-vrx2-77f2-ww34
advisory-database[bot] Apr 22, 2026
e6ec74f
Advisory Database Sync
advisory-database[bot] Apr 22, 2026
c0e0f97
Publish GHSA-95ww-475f-pr4f
advisory-database[bot] Apr 22, 2026
410e19a
Publish Advisories
advisory-database[bot] Apr 22, 2026
5269f5d
Publish GHSA-jxpf-xq2m-q525
advisory-database[bot] Apr 22, 2026
4aa24cb
Publish GHSA-wgx6-g857-jjf7
advisory-database[bot] Apr 22, 2026
71d90d7
Publish Advisories
advisory-database[bot] Apr 22, 2026
9b50058
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
7081720
Publish Advisories
advisory-database[bot] Apr 23, 2026
baafd1f
Publish Advisories
advisory-database[bot] Apr 23, 2026
17e66de
Publish Advisories
advisory-database[bot] Apr 23, 2026
007bf09
Publish Advisories
advisory-database[bot] Apr 23, 2026
0753416
Publish GHSA-v529-vhwc-wfc5
advisory-database[bot] Apr 23, 2026
f8cd9e3
Publish GHSA-2wvh-87g2-89hr
advisory-database[bot] Apr 23, 2026
31ef4ec
Publish Advisories
advisory-database[bot] Apr 23, 2026
dbaef2f
Publish GHSA-rhf7-wvw3-vjvm
advisory-database[bot] Apr 23, 2026
edbab1f
Publish Advisories
advisory-database[bot] Apr 23, 2026
fae8b84
Publish GHSA-c57f-mm3j-27q9
advisory-database[bot] Apr 23, 2026
935bf83
Publish GHSA-jvff-x2qm-6286
advisory-database[bot] Apr 23, 2026
4640a01
Publish GHSA-9mv3-2cwr-p262
advisory-database[bot] Apr 23, 2026
faaa372
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
a7b931b
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
44ea97a
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
1d4b105
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
b7f774a
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
26a7e67
Publish GHSA-c2jg-5cp7-6wc7
advisory-database[bot] Apr 23, 2026
f83a998
Publish Advisories
advisory-database[bot] Apr 23, 2026
a044e23
Publish Advisories
advisory-database[bot] Apr 23, 2026
d0175c6
Publish GHSA-q834-8qmm-v933
advisory-database[bot] Apr 23, 2026
fdb75ec
Advisory Database Sync
advisory-database[bot] Apr 23, 2026
9df6bb9
Publish Advisories
advisory-database[bot] Apr 23, 2026
54352ff
Publish Advisories
advisory-database[bot] Apr 23, 2026
bb1fcf8
Publish Advisories
advisory-database[bot] Apr 23, 2026
5c3bc54
Publish Advisories
advisory-database[bot] Apr 23, 2026
123f4ca
Publish GHSA-88gm-j2wx-58h6
advisory-database[bot] Apr 23, 2026
8fbc646
Publish Advisories
advisory-database[bot] Apr 23, 2026
83d9767
Advisory Database Sync
advisory-database[bot] Apr 24, 2026
f4a918d
Publish Advisories
advisory-database[bot] Apr 24, 2026
109002a
Publish Advisories
advisory-database[bot] Apr 24, 2026
f2e5a9c
Publish Advisories
advisory-database[bot] Apr 24, 2026
1433a5a
Publish Advisories
advisory-database[bot] Apr 24, 2026
f495266
Publish GHSA-hfpq-x728-986j
advisory-database[bot] Apr 24, 2026
36c5a42
Publish GHSA-pr46-2v3c-5356
advisory-database[bot] Apr 24, 2026
439cff0
Publish GHSA-x4mj-7f9g-29h4
advisory-database[bot] Apr 24, 2026
d208074
Publish Advisories
advisory-database[bot] Apr 24, 2026
baa442d
Publish Advisories
advisory-database[bot] Apr 24, 2026
17a2dab
Advisory Database Sync
advisory-database[bot] Apr 24, 2026
f393ced
Publish Advisories
advisory-database[bot] Apr 24, 2026
93b8056
Publish Advisories
advisory-database[bot] Apr 24, 2026
8cbe008
Publish GHSA-xff3-5c9p-2mr4
advisory-database[bot] Apr 24, 2026
7dd1860
Publish GHSA-58qw-9mgm-455v
advisory-database[bot] Apr 24, 2026
d2a3145
Publish GHSA-38c5-483c-4qqp
advisory-database[bot] Apr 24, 2026
c4814b4
Publish Advisories
advisory-database[bot] Apr 24, 2026
18f5d47
Publish GHSA-xqmj-j6mv-4862
advisory-database[bot] Apr 24, 2026
9cf7b42
Publish GHSA-qc5p-3mg5-9fh8
advisory-database[bot] Apr 24, 2026
08dc98f
Publish GHSA-5wfc-hjrc-gq87
advisory-database[bot] Apr 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
2 changes: 1 addition & 1 deletion .github/workflows/create_staging_branch.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
ensure-base-is-staging:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v6
- name: ensure base is staging
env:
PR_AUTHOR: ${{ github.event.pull_request.user.login }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/delete_staging_and_head_branches.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
if: ${{ !github.event.pull_request.head.repo.fork }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v6
- name: Delete staging and head branches
env:
STAGING_BRANCH: ${{ github.event.pull_request.base.ref }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/stale.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/stale@v9.0.0
- uses: actions/stale@v10.0.0
name: Clean up stale PRs
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6wpv-cj6x-v3jw",
"modified": "2023-01-25T23:04:00Z",
"modified": "2026-04-17T19:00:58Z",
"published": "2018-03-13T16:15:57Z",
"aliases": [
"CVE-2015-1828"
],
"summary": "http vulnerable to Exposure of Sensitive Information to an Unauthorized Actor",
"details": "The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.",
"details": "The Ruby http gem before 0.6.4 and 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.",
"severity": [
{
"type": "CVSS_V3",
Expand All @@ -25,14 +25,33 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
"introduced": "0.7.0"
},
{
"fixed": "0.7.3"
}
]
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "http"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.6.4"
}
]
}
]
}
],
"references": [
Expand All @@ -44,6 +63,10 @@
"type": "WEB",
"url": "https://github.com/ruby/openssl/issues/8"
},
{
"type": "PACKAGE",
"url": "https://github.com/httprb/http"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/http/CVE-2015-1828.yml"
Expand All @@ -52,6 +75,14 @@
"type": "WEB",
"url": "https://groups.google.com/forum/#!topic/httprb/jkb4oxwZjkU"
},
{
"type": "WEB",
"url": "https://my.diffend.io/gems/http/0.6.3/0.6.4"
},
{
"type": "WEB",
"url": "https://my.diffend.io/gems/http/0.7.2/0.7.3"
},
{
"type": "WEB",
"url": "https://rubysec.com/advisories/http-CVE-2015-1828"
Expand All @@ -64,6 +95,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:20:24Z",
"nvd_published_at": null
"nvd_published_at": "2017-10-06T22:29:00Z"
}
}
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vrh8-27q8-fr8f",
"modified": "2022-09-17T00:09:39Z",
"modified": "2026-04-16T16:55:49Z",
"published": "2019-03-14T15:39:56Z",
"aliases": [
"CVE-2017-3164"
Expand All @@ -25,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.30"
"introduced": "1.3.0"
},
{
"fixed": "7.7.0"
Expand All @@ -43,10 +43,6 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-3164"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-vrh8-27q8-fr8f"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/43026507844ada1ac658ccf7bc939378c13e492fd6538416ce65df39@%3Cdev.lucene.apache.org%3E"
Expand Down Expand Up @@ -77,23 +73,19 @@
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20190327-0003"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2020.html"
"url": "http://mail-archives.apache.org/mod_mbox/www-announce/201902.mbox/%3CCAECwjAVjBN%3DwO5rYs6ktAX-5%3D-f5JDFwbbTSM2TTjEbGO5jKKA%40mail.gmail.com%3E"
},
{
"type": "WEB",
"url": "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
"url": "http://security.netapp.com/advisory/ntap-20190327-0003"
},
{
"type": "WEB",
"url": "http://mail-archives.apache.org/mod_mbox/www-announce/201902.mbox/%3CCAECwjAVjBN%3DwO5rYs6ktAX-5%3D-f5JDFwbbTSM2TTjEbGO5jKKA%40mail.gmail.com%3E"
"url": "http://www.oracle.com/security-alerts/cpuoct2020.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/107026"
"url": "http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
}
],
"database_specific": {
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gxr4-xjj5-5px2",
"modified": "2025-01-31T20:49:05Z",
"modified": "2026-04-13T13:53:37Z",
"published": "2020-04-29T22:18:55Z",
"aliases": [
"CVE-2020-11022"
Expand All @@ -25,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
"introduced": "1.12.0"
},
{
"fixed": "3.5.0"
Expand All @@ -44,7 +44,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
"introduced": "1.12.0"
},
{
"fixed": "3.5.0"
Expand Down Expand Up @@ -82,7 +82,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
"introduced": "1.12.0"
},
{
"fixed": "3.5.0"
Expand Down Expand Up @@ -139,7 +139,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
"introduced": "1.12.0"
},
{
"fixed": "3.5.0"
Expand Down Expand Up @@ -172,35 +172,35 @@
},
{
"type": "WEB",
"url": "https://blog.jquery.com/2020/04/10/jquery-3-5-0-released"
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B"
"url": "https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W"
"url": "https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202007-03"
"url": "https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20200511-0006"
"url": "https://packetstormsecurity.com/files/162159/jQuery-1.2-Cross-Site-Scripting.html"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2020/dsa-4693"
"url": "https://security.gentoo.org/glsa/202007-03"
},
{
"type": "WEB",
"url": "https://www.drupal.org/sa-core-2020-002"
"url": "https://www.debian.org/security/2020/dsa-4693"
},
{
"type": "WEB",
"url": "https://www.npmjs.com/advisories/1518"
"url": "https://www.drupal.org/sa-core-2020-002"
},
{
"type": "WEB",
Expand Down Expand Up @@ -255,8 +255,8 @@
"url": "https://www.tenable.com/security/tns-2021-10"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-gxr4-xjj5-5px2"
"type": "WEB",
"url": "https://blog.jquery.com/2020/04/10/jquery-3-5-0-released"
},
{
"type": "PACKAGE",
Expand Down Expand Up @@ -340,19 +340,11 @@
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html"
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/162159/jQuery-1.2-Cross-Site-Scripting.html"
"url": "http://security.netapp.com/advisory/ntap-20200511-0006"
}
],
"database_specific": {
Expand Down
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxhc-q857-3j6g",
"modified": "2021-08-30T22:21:20Z",
"modified": "2026-04-06T23:12:46Z",
"published": "2021-07-12T16:58:33Z",
"aliases": [
"CVE-2021-32740"
],
"summary": "Regular Expression Denial of Service in Addressable templates",
"details": "### Impact\n\nWithin the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected.\n\n### Patches\n\nThe vulnerability was introduced in version 2.3.0 (previously yanked) and has been present in all subsequent versions up to, and including, 2.7.0. It is fixed in version 2.8.0.\n\n### Workarounds\n\nThe vulnerability can be avoided by only creating Template objects from trusted sources that have been validated not to produce catastrophic backtracking.\n\n### References\n\n- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS\n- https://cwe.mitre.org/data/definitions/1333.html\n- https://www.regular-expressions.info/catastrophic.html\n\n### For more information\nIf you have any questions or comments about this advisory:\n* [Open an issue](https://github.com/sporkmonger/addressable/issues)\n",
"details": "### Impact\n\nWithin the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected.\n\n### Patches\n\nThe vulnerability was introduced in version 2.3.0 (previously yanked) and has been present in all subsequent versions up to, and including, 2.7.0. It is fixed in version 2.8.0.\n\n### Workarounds\n\nThe vulnerability can be avoided by only creating Template objects from trusted sources that have been validated not to produce catastrophic backtracking.\n\n### References\n\n- https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS\n- https://cwe.mitre.org/data/definitions/1333.html\n- https://www.regular-expressions.info/catastrophic.html\n\n### For more information\nIf you have any questions or comments about this advisory:\n* [Open an issue](https://github.com/sporkmonger/addressable/issues)",
"severity": [
{
"type": "CVSS_V3",
Expand Down Expand Up @@ -82,6 +82,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1333",
"CWE-400"
],
"severity": "HIGH",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mxh-2qfv-4g7j",
"modified": "2022-04-05T19:29:23Z",
"modified": "2026-04-15T21:11:17Z",
"published": "2021-11-10T20:15:06Z",
"aliases": [
"CVE-2021-3910"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75vw-3m5v-fprh",
"modified": "2022-01-24T22:08:31Z",
"modified": "2026-04-14T23:55:03Z",
"published": "2022-01-21T23:43:11Z",
"aliases": [
"CVE-2022-0239"
Expand All @@ -28,18 +28,29 @@
"introduced": "0"
},
{
"last_affected": "4.3.2"
"fixed": "4.4.0"
}
]
}
]
],
"database_specific": {
"last_known_affected_version_range": "<= 4.3.2"
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0239"
},
{
"type": "WEB",
"url": "https://github.com/stanfordnlp/CoreNLP/pull/1242"
},
{
"type": "WEB",
"url": "https://github.com/stanfordnlp/CoreNLP/commit/f44e693882812b144e09d39850177ff0a1f8d16f"
},
{
"type": "WEB",
"url": "https://github.com/stanfordnlp/corenlp/commit/1940ffb938dc4f3f5bc5f2a2fd8b35aabbbae3dd"
Expand All @@ -51,6 +62,10 @@
{
"type": "WEB",
"url": "https://huntr.dev/bounties/a717aec2-5646-4a5f-ade0-dadc25736ae3"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JAVA-EDUSTANFORDNLP-2342121"
}
],
"database_specific": {
Expand Down
Loading
Loading