Skip to content

Require patched REXML version - #889

Merged
sds merged 1 commit into
mainfrom
fix/rexml-cve-2025-58767
Aug 1, 2026
Merged

Require patched REXML version#889
sds merged 1 commit into
mainfrom
fix/rexml-cve-2025-58767

Conversation

@sds

@sds sds commented Aug 1, 2026

Copy link
Copy Markdown
Owner

Fixes #874.

Raise the minimum REXML runtime dependency from 3.3.9 to 3.4.2, the first release containing the fix for CVE-2025-58767. This prevents downstream Bundler resolution from selecting an affected REXML release.

@sds
sds merged commit 9338179 into main Aug 1, 2026
18 checks passed
@sds
sds deleted the fix/rexml-cve-2025-58767 branch August 1, 2026 19:41
@sds sds added the enhancement label Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: CVE-2025-58767 via rexml 3.3.9 dependency

1 participant