Skip to content

GHSA-jr95-x3fr-rcg4: add affected RubyGems ranges for resolv - #9592

Open
brianmcarey wants to merge 1 commit into
github:brianmcarey/advisory-improvement-9592from
brianmcarey:brianmcarey-GHSA-jr95-x3fr-rcg4
Open

brianmcarey wants to merge 1 commit into
github:brianmcarey/advisory-improvement-9592from
brianmcarey:brianmcarey-GHSA-jr95-x3fr-rcg4

Conversation

@brianmcarey

Copy link
Copy Markdown

GHSA-jr95-x3fr-rcg4 (CVE-2026-80213) has an empty affected array, so the advisory carries no package or version information and cannot be matched against pkg:gem/resolv. The record already has accurate details, severity and CWE; this only adds the affected ranges.

The ranges come from the upstream Ruby advisory, which lists the affected versions as "resolv gem 0.4.0 through 0.7.1" and "resolv gem 0.3.1 and earlier", fixed in 0.7.2 with a 0.3.2 backport for the 0.3.x line used by the Ruby 3.3 series. No release is planned for the 0.2.x line shipped by the end-of-life Ruby 3.2 series, so 0 to 0.3.2 covers it.

This matches the shape already used for the earlier resolv advisory GHSA-xh69-987w-hrp8, and the same ranges are recorded in rubysec/ruby-advisory-db.

References:

@github-actions
github-actions Bot changed the base branch from main to brianmcarey/advisory-improvement-9592 September 17, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant