resque
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them later.
Activity
- Latest release
- 4d ago
- Total releases
- 82
- Cadence
- ~41 days
- Last 12 months
- 4
Reach
- Downloads
- 54.6M
- Stars
- 9.5k
Details
- License
- MIT
- First release
- Nov 03, 2009
| Version | Released | |
|---|---|---|
3.0.3
patch
|
3.0.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.2
patch
|
3.0.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.1
patch
|
3.0.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.0
major
|
3.0.0
major
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.7.0
minor
| ||
2.6.0
minor
| ||
2.5.0
minor
1 CVE
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
major
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.27.4
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.27.3
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.27.2
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.27.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.27.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.26.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.25.2
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.26.pre.0
pre
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.25.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.25.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.25.0.pre
pre
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.24.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.24.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.23.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.23.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.22.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.21.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.20.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.19.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.6
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.5
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.4
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.3
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.2
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.18.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.17.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.17.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.16.1
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.16.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.15.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.14.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.0
minor
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.10
patch
3 CVEs
CVE-2023-50724
GHSA-r8xx-8vm8-x6wj
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
Impactresque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. Patchesv2.1.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 58 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50725
GHSA-gc3j-vvwf-4rp8
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactThe following paths in resque-web have been found to be vulnerable to reflected XSS:
Patchesv2.2.1 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1790 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 60 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50727
GHSA-r9mq-m72x-257g
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
6.3
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
High
None
ImpactReflected XSS can be performed using the current_queue portion of the path on the /queues endpoint of resque-web. Patchesv2.6.0 WorkaroundsNo known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application. Referenceshttps://github.com/resque/resque/pull/1865 Affected versions
0.2.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
+ 64 more Show less
1.17.1
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.19.0
1.2.0
1.2.1
1.2.3
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.25.0.pre
1.25.1
1.25.2
1.26.0
1.26.pre.0
1.27.0
1.27.1
1.27.2
1.27.3
1.27.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.7
1.9.8
1.9.9
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
Fixed in
2.6.0
References
Updated Sep 10, 2026 · Source: OSV.dev |