Real-time CVE monitoring
CVE alerts for
Ruby
CVEye scans every new CVE and notifies your team the moment Ruby is affected — before attackers can exploit it.
Monitor Ruby free →No credit card · 7-day trial
Recent Ruby CVEs
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Never miss a Ruby vulnerability
CVEye monitors Ruby and your entire stack 24/7, sending instant alerts via email, Slack, Discord, or webhook the moment a new CVE is published.
7-day free trial · No credit card required