Skip to content

Update advisory to include new release today#1066

Open
jasnow wants to merge 1 commit into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-05-23-16_55_59
Open

Update advisory to include new release today#1066
jasnow wants to merge 1 commit into
rubysec:masterfrom
jasnow:ghsa-syncbot-2026-05-23-16_55_59

Conversation

@jasnow
Copy link
Copy Markdown
Contributor

@jasnow jasnow commented May 23, 2026

Update advisory to include new release today

FYI: https://rubygems.org/gems/iodine

url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-41146
- https://github.com/boazsegev/iodine/releases/tag/v0.7.58
- https://github.com/boazsegev/iodine/releases/tag/v0.7.59
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I tried, but could not quickly confirm that this release contained the commit with the fix mentioned in the GHSA. Neither the GHSA nor the CVE state a fixed version.

Can you help the reader of this report understand how you got this information? Is there a changelog entry that I missed or release notes or something?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

working

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants