Sep 25 GHSA-42qh-8mx8-7wqm (rack-proxy): HTTP response smuggling via ambiguous backend response framing in rack-proxy 1.x posted in •
Sep 24 GHSA-6wmv-xq9m-fmp7 (dalli): Memcached command injection through numeric arguments to incr/decr and fetch_with_lock posted in •
Sep 15 GHSA-p8jg-8p9f-pgmr (faraday-http-cache): Cache entries deserialized with JSON.load can instantiate arbitrary classes named by an origin server posted in •
Sep 15 GHSA-c33f-42f2-gwcc (faraday-http-cache): Shared cache serves responses to authenticated requests to other callers posted in •
Sep 10 CVE-2026-88030 (mongo): MongoDB Ruby Driver - Improper neutralization of special elements in data query logic in the GridFS component posted in •
Sep 02 GHSA-g7vv-4mjj-6fgm (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog posted in •
Sep 02 GHSA-4qhx-6wrv-5hg2 (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Admin Configure Dialog Page Content posted in •
Aug 27 CVE-2026-81097 (rails-mcp-server): The execute_ruby tool is documented as a read-only Ruby sandbox posted in •