MEDIUM4.7RubyGems
GHSA-rqq5-2gf9-4w4q· CVE-2026-54163Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Modified: 7/10/2026
package
pkg:rubygems/secure_headers
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Modified: 7/10/2026
Limited header injection when using dynamic overrides with user input in RubyGems secure_headers
Modified: 7/8/2026
Directive injection when using dynamic overrides with user input
Modified: 9/10/2026