decidim-verifications
RubyGems3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting decidim-verificationspage 1 of 1
- CVE-2026-45330MEDIUMCVSS 4.9EG 4.9✓ Fixed in 0.32.02026-07-13
vulnerable: 0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc3
Decidim: Verification admins can access supplied IDs from other organizations ## Description The verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. ## Technical descrip…
- CVE-2026-45378HIGHCVSS 7.5EG 7.5✓ Fixed in 0.32.02026-07-13
vulnerable: 0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc3
Decidim: Verification documents can be downloaded through reusable links ## Description Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed `/rails/active_stor…
- CVE-2026-45415MEDIUMCVSS 6.0EG 6.0✓ Fixed in 0.32.02026-07-13
vulnerable: 0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc3
Decidim: CSV census record endpoints improper authorization ## Description A participant manager can access and modify the CSV census record admin forms. ## Technical description The CSV census admin record-management surface under `/a…
Check whether decidim-verifications is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for decidim-verifications CVEs against the assets you own.
Start Free Scan →