Skip to content

fix css_parser CVE-2026-53727 - #1220

Open
grosser wants to merge 1 commit into
rubysec:masterfrom
grosser:grosser/css
Open

fix css_parser CVE-2026-53727#1220
grosser wants to merge 1 commit into
rubysec:masterfrom
grosser:grosser/css

Conversation

@grosser

@grosser grosser commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

Comment on lines 25 to +26
unaffected_versions:
- "< 2.2.0"
- ">= 3.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@grosser inspired by the last line of your comment I think the unaffected_versions section can be removed now it matches patched_versions.

If we look at this other recently added advisory for example, it has the patched_versions section but not unaffected_versions: https://github.com/rubysec/ruby-advisory-db/blob/2833c74c9d9b8848a56463d5fad4ddcd9c53a331/gems/activestorage/CVE-2026-66066.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants