Skip to content

New advisory - see Ruby 4.0.5#1063

Merged
flavorjones merged 2 commits into
rubysec:masterfrom
jasnow:ruby-adv-may26
May 23, 2026
Merged

New advisory - see Ruby 4.0.5#1063
flavorjones merged 2 commits into
rubysec:masterfrom
jasnow:ruby-adv-may26

Conversation

@jasnow
Copy link
Copy Markdown
Contributor

@jasnow jasnow commented May 23, 2026

New advisory - see Ruby 4.0.5

  • rubies/ruby/CVE-2026-46727.yml

Comment thread rubies/ruby/CVE-2026-46727.yml Outdated
This issue has been fixed in Ruby 4.0.5. We recommend upgrading Ruby.
cvss_v3: 8.1
unaffected_versions:
- "<= 3.4"
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think I would prefer this to be < 4.0 for clarity. "3.4" without a patch version can be confusing when an "=" is used. (For example, it's not clear that "3.4.1" <= "3.4".)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added commit

@flavorjones flavorjones merged commit a9b0a73 into rubysec:master May 23, 2026
1 check passed
@jasnow jasnow deleted the ruby-adv-may26 branch May 23, 2026 20:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants