decidim-verifications
RubyGems3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting decidim-verificationspage 1 of 1
- CVE-2026-45330MEDIUMCVSS 4.9EG 4.9✓ Fixed in 0.32.02026-07-13
vulnerable: 0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier with…
- CVE-2026-45378HIGHCVSS 7.5EG 7.5✓ Fixed in 0.32.02026-07-13
vulnerable: 0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Activ…
- CVE-2026-45415MEDIUMCVSS 6.0EG 6.0✓ Fixed in 0.32.02026-07-13
vulnerable: 0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization …
Check whether decidim-verifications is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for decidim-verifications CVEs against the assets you own.
Start Free Scan →