Rubygems is the package repository and package-management ecosystem for the Ruby programming language, whose widespread adoption across web applications and infrastructure automation means that vulnerabilities in the repository infrastructure or popular gems can propagate to a large installed base despite the vendor's narrow product footprint. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through weakness classes characteristic of dynamic-language ecosystems: improper input validation, code injection, path traversal, injection attacks, and unsafe deserialization of untrusted data—all of which can allow remote code execution when gem dependencies are installed or updated. The exposure concentrates in the core rubygems package manager, rubygems.org repository itself, and widely used gems such as mail_gem and command_wrap, where these weaknesses translate to supply-chain risk for any project that pulls those dependencies. Defenders should monitor this vendor's advisories and coordinate patching across their Ruby dependency trees, treating gem updates as a security-critical function; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rubygems over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0901HIGH RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem. | Aug 31, 2017 | 7.5 | 43 | NO | YES |
CVE-2017-0903CRITICAL RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists | Oct 11, 2017 | 9.8 | 34 | NO | NO |
CVE-2013-0269HIGH The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assign | Feb 13, 2013 | 7.5 | 31 | NO | NO |
CVE-2024-21654CRITICAL Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeove | Jan 12, 2024 | 9.8 | 30 | NO | NO |
CVE-2018-1000076CRITICAL RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revi | Mar 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-0899CRITICAL RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute te | Aug 31, 2017 | 9.8 | 28 | NO | NO |
CVE-2012-2140HIGH The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery. | Jul 18, 2012 | 7.5 | 27 | NO | NO |
CVE-2022-36073HIGH RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email | Sep 7, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-29176HIGH Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and rep | May 5, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-29218HIGH RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms e | May 13, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rubygems.
Media articles that mention a CVE ID that affects a product developed by Rubygems — matched by CVE ID, not by vendor name.