Skip to main content

Vendor/product archive

heartcombo / devise CVEs

Beta · best-effort

3 CVEs tagged to heartcombo / devise0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-40295

Published May 22, 2026

Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method r…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32700

Published Mar 18, 2026

Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email addr…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2015-8314

Published Dec 12, 2023

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1