MEDIUM5.3RubyGems
GHSA-57hq-95w6-v4fc· CVE-2026-32700Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Modified: 3/30/2026
package
pkg:rubygems/devise
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Modified: 3/30/2026
devise Time-of-check Time-of-use Race Condition vulnerability
Modified: 11/30/2024
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
Modified: 2/4/2026
Authentication Bypass in Devise
Modified: 2/16/2024
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
Modified: 9/10/2026
Devise does not properly perform type conversion when performing database queries
Modified: 12/3/2024