Skip to content

Comments

Add patched version for CVE-2026-25765#992

Merged
postmodern merged 2 commits intorubysec:masterfrom
toddsiegel:master
Feb 13, 2026
Merged

Add patched version for CVE-2026-25765#992
postmodern merged 2 commits intorubysec:masterfrom
toddsiegel:master

Conversation

@toddsiegel
Copy link
Contributor

The fix for this was backported to 1.x versions as well.

See:

@jasnow
Copy link
Contributor

jasnow commented Feb 12, 2026

Can you please add the commit url under "related:/url:" section. Thanks.

@toddsiegel
Copy link
Contributor Author

Done.

The fix for this was backported to 1.x versions

See:
- lostisland/faraday@d0fc049beb
- GHSA-33mh-2634-fwr2
Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only the last patched version number should start with a >=. The previous patched versions should use ~>.

@rubysec rubysec deleted a comment from jasnow Feb 13, 2026
…6-25765.yml`

* Only the last patched version may use the `>=` operator.
@postmodern postmodern merged commit e8607af into rubysec:master Feb 13, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants