Skip to content

🚨 [security] [ruby] Update addressable 2.8.7 β†’ 2.9.0 (minor) - #313

Open
depfu[bot] wants to merge 1 commit into
mainfrom
depfu/update/addressable-2.9.0
Open

🚨 [security] [ruby] Update addressable 2.8.7 β†’ 2.9.0 (minor)#313
depfu[bot] wants to merge 1 commit into
mainfrom
depfu/update/addressable-2.9.0

Update addressable to version 2.9.0

2f37e41
Select commit
Loading
Failed to load commit list.
Cirrus CI / bundle-audit failed Apr 8, 2026 in 28s

Task Summary

Instruction audit failed in 00:02

Details

⚠️ Not enough compute credits to prioritize tasks!

βœ… 00:00 clone
βœ… 00:06 os_setup
βœ… 00:01 rbenv_setup
βœ… 00:10 rbenv
βœ… 00:01 bundle
βœ… 00:04 install
❌ 00:02 audit

Solution: update to '~> 1.10.5', '>= 2.14.1'

Name: nokogiri
Version: 1.18.9
GHSA: GHSA-wx95-c6cv-8532
Criticality: Medium
URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532
Title: Nokogiri does not check the return value from xmlC14NExecute
Solution: update to '>= 1.19.1'

Name: rack
Version: 3.2.2
CVE: CVE-2025-61780
GHSA: GHSA-r657-rxjc-j557
Criticality: Medium
URL: https://github.com/rack/rack/security/advisories/GHSA-r657-rxjc-j557
Title: Rack has a Possible Information Disclosure Vulnerability
Solution: update to '~> 2.2.20', '~> 3.1.18', '>= 3.2.3'

Name: rack
Version: 3.2.2
CVE: CVE-2025-61919
GHSA: GHSA-6xw4-3v39-52mm
Criticality: High
URL: https://github.com/rack/rack/security/advisories/GHSA-6xw4-3v39-52mm
Title: Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
Solution: update to '~> 2.2.20', '~> 3.1.18', '>= 3.2.3'

Name: rack
Version: 3.2.2
CVE: CVE-2026-22860
GHSA: GHSA-mxw3-3hh2-x2mh
Criticality: High
URL: https://github.com/rack/rack/security/advisories/GHSA-mxw3-3hh2-x2mh
Title: Rack has a Directory Traversal via Rack:Directory
Solution: update to '~> 2.2.22', '~> 3.1.20', '>= 3.2.5'

Name: rack
Version: 3.2.2
CVE: CVE-2026-25500
GHSA: GHSA-whrj-4476-wvmp
Criticality: Medium
URL: https://github.com/rack/rack/security/advisories/GHSA-whrj-4476-wvmp
Title: Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
Solution: update to '~> 2.2.22', '~> 3.1.20', '>= 3.2.5'

Name: uri
Version: 1.0.3
CVE: CVE-2025-61594
GHSA: GHSA-j4pr-3wm6-xx2r
Criticality: Unknown
URL: https://www.ruby-lang.org/en/news/2025/10/07/uri-cve-2025-61594
Title: CVE-2025-61594 - URI Credential Leakage Bypass over CVE-2025-27221
Solution: update to '~> 0.12.5', '~> 0.13.3', '>= 1.0.4'

Vulnerabilities found!