Security: heartcombo/devise
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout HandlerGHSA-jp94-3292-c3xv published
May 8, 2026 by carlosantoniodasilvaModerate -
Confirmable "change email" race condition permits user to confirm email they have no access toGHSA-57hq-95w6-v4fc published
Mar 16, 2026 by carlosantoniodasilvaModerate
Learn more about advisories related to heartcombo/devise in the GitHub Advisory Database