Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rubygems

First CVE: Jul 18, 2012Active for: 14 yearsTotal CVEs: 35
50.3
VTI Score
TOP TARGET

Rubygems is the package repository and package-management ecosystem for the Ruby programming language, whose widespread adoption across web applications and infrastructure automation means that vulnerabilities in the repository infrastructure or popular gems can propagate to a large installed base despite the vendor's narrow product footprint. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through weakness classes characteristic of dynamic-language ecosystems: improper input validation, code injection, path traversal, injection attacks, and unsafe deserialization of untrusted data—all of which can allow remote code execution when gem dependencies are installed or updated. The exposure concentrates in the core rubygems package manager, rubygems.org repository itself, and widely used gems such as mail_gem and command_wrap, where these weaknesses translate to supply-chain risk for any project that pulls those dependencies. Defenders should monitor this vendor's advisories and coordinate patching across their Ruby dependency trees, treating gem updates as a security-critical function; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rubygems over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 18, 2012
14 years ago
Most Recent CVE
Jan 12, 2024
925 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-0901HIGH
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Aug 31, 20177.543NOYES
CVE-2017-0903CRITICAL
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists
Oct 11, 20179.834NONO
CVE-2013-0269HIGH
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assign
Feb 13, 20137.531NONO
CVE-2024-21654CRITICAL
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeove
Jan 12, 20249.830NONO
CVE-2018-1000076CRITICAL
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revi
Mar 13, 20189.829NONO
CVE-2017-0899CRITICAL
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute te
Aug 31, 20179.828NONO
CVE-2012-2140HIGH
The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery.
Jul 18, 20127.527NONO
CVE-2022-36073HIGH
RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email
Sep 7, 20228.826NONO
CVE-2022-29176HIGH
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and rep
May 5, 20227.526NONO
CVE-2022-29218HIGH
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms e
May 13, 20227.525NONO
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
29%
60%
11%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.7%)
Network21 (60.0%)
Unknown12 (34.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (57.1%)
High3 (8.6%)
Unknown12 (34.3%)
User Interaction
None19 (54.3%)
Unknown12 (34.3%)
Required4 (11.4%)
Privileges Required
Low2 (5.7%)
High0 (0.0%)
None21 (60.0%)
Unknown12 (34.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rubygems.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rubygems — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rubygems's Products

View all 4 CNAs →

Top CWEs