Skip to content

Add view_component 3.25.0 as patched for CVE-2026-44836 and CVE-2026-44837#1109

Merged
jasnow merged 1 commit into
rubysec:masterfrom
kwent:view-component-3.25.0-patch
Jun 9, 2026
Merged

Add view_component 3.25.0 as patched for CVE-2026-44836 and CVE-2026-44837#1109
jasnow merged 1 commit into
rubysec:masterfrom
kwent:view-component-3.25.0-patch

Conversation

@kwent

@kwent kwent commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

Summary

v3.25.0 backports both security fixes (CVE-2026-44836, CVE-2026-44837) to the 3.x branch. The maintainer released this as a direct response to a backport request.

Changes

  • gems/view_component/CVE-2026-44836.yml — added >= 3.25.0, < 4.0.0 to patched_versions
  • gems/view_component/CVE-2026-44837.yml — added >= 3.25.0, < 4.0.0 to patched_versions

@simi

simi commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Looks great. Thanks @kwent!

@jasnow jasnow merged commit 4ddbd71 into rubysec:master Jun 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants