See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applications| VULNERABILITY | AFFECTS | TYPE | PUBLISHED |
|---|---|---|---|
| phlex<1.0.1>=1.1.0, <1.1.1>=1.2.0, <1.2.2>=1.3.0, <1.3.3>=1.4.0, <1.4.1>=1.5.0, <1.5.2>=1.6.0, <1.6.2>=1.7.0, <1.7.1>=1.8.0, <1.8.2>=1.9.0, <1.9.1 | RubyGems | 13 Mar 2024 |
| stimulus_reflex<3.4.2>=3.5.0-pre0, <3.5.0-rc4 | RubyGems | 13 Mar 2024 |
| yard<0.9.35 | RubyGems | 29 Feb 2024 |
| actionpack>=5.2.0, <6.1.7.7>=7.0.0, <7.0.8.1 | RubyGems | 25 Feb 2024 |
| actionpack>=7.1.0, <7.1.3.1 | RubyGems | 25 Feb 2024 |
| actionpack>=7.0.0, <7.0.8.1>=7.1.0, <7.1.3.1 | RubyGems | 25 Feb 2024 |
| rack>=1.3.0, <2.2.8.1>=3.0.0, <3.0.9.1 | RubyGems | 25 Feb 2024 |
| rack>=0.4.0, <2.2.8.1>=3.0.0, <3.0.9.1 | RubyGems | 25 Feb 2024 |
| rack<2.0.9.4>=2.1.0, <2.1.4.4>=2.2.0, <2.2.8.1>=3.0.0, <3.0.9.1 | RubyGems | 25 Feb 2024 |
| decidim>=0.27.0, <0.27.5 | RubyGems | 22 Feb 2024 |
| decidim-core>=0.27.0, <0.27.5 | RubyGems | 22 Feb 2024 |
| decidim>=0.10.0, <0.26.9>=0.27.0, <0.27.5 | RubyGems | 21 Feb 2024 |
| decidim-templates>=0.23.0, <0.27.5 | RubyGems | 21 Feb 2024 |
| decidim-system>=0.0.1, <0.26.9>=0.27.0, <0.27.5 | RubyGems | 21 Feb 2024 |
| decidim-admin>=0.0.1, <0.26.9>=0.27.0, <0.27.5 | RubyGems | 21 Feb 2024 |
| devise_invitable>=0.4.0, <2.0.9 | RubyGems | 21 Feb 2024 |
| sidekiq-unique-jobs<7.1.33>=8.0.0, <8.0.7 | RubyGems | 14 Feb 2024 |
| nokogiri<1.15.6>=1.16.0, <1.16.2 | RubyGems | 5 Feb 2024 |
| avo<3.0.2 | RubyGems | 18 Jan 2024 |
| avo<2.47.0>=3.0.0.beta1, <3.3.0 | RubyGems | 18 Jan 2024 |
| puma<5.6.8>=6.0.0, <6.4.2 | RubyGems | 9 Jan 2024 |
| encoded_id<1.0.0.rc3 | RubyGems | 5 Jan 2024 |
| view_component<2.83.0>=3.0.0, <3.9.0 | RubyGems | 5 Jan 2024 |
| omniauth-microsoft_graph<2.0.0 | RubyGems | 3 Jan 2024 |
| json-jwt<1.15.3.1>=1.16.0, <1.16.6 | RubyGems | 27 Dec 2023 |
| activeadmin<3.2.0 | RubyGems | 24 Dec 2023 |
| resque-scheduler<4.10.2 | RubyGems | 20 Dec 2023 |
| resque<2.2.1 | RubyGems | 19 Dec 2023 |
| resque<2.6.0 | RubyGems | 19 Dec 2023 |
| resque<2.1.0 | RubyGems | 19 Dec 2023 |