Skip to content

Two new (mruby, mongo-ruby-driver) advisories - #1241

Merged
jasnow merged 3 commits into
rubysec:masterfrom
jasnow:sep-11-advs
Sep 13, 2026
Merged

Two new (mruby, mongo-ruby-driver) advisories#1241
jasnow merged 3 commits into
rubysec:masterfrom
jasnow:sep-11-advs

Conversation

@jasnow

@jasnow jasnow commented Sep 11, 2026

Copy link
Copy Markdown
Member

Two new (mruby, mongo-ruby-driver) advisories

@jasnow
jasnow requested review from flavorjones and simi September 12, 2026 00:27

@flavorjones flavorjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Thanks for these. One blocking problem and two small ones.

Blocking: gem: mongo-ruby-driver names a gem that does not exist on rubygems.org (the API returns 404). The gem is mongo, so this file belongs at gems/mongo/CVE-2026-88030.yml with gem: mongo. As written, bundler-audit never matches it.

Minor: the description drops the last letter of "application" (the GHSA text has it), and the mruby fix commit c6866ee is already in tag 4.1.0-rc, so >= 4.1.0-rc matches the actual fix range (precedent: rubies/mruby/CVE-2021-46020.yml uses >= 3.1.0-rc).

Everything else checks out against GHSA-4ww7-gqv6-mffc, GHSA-q9f2-rhj2-x3xg, rubygems, the v2.26.0 release notes, and mruby's NEWS.md.

Comment thread gems/mongo-ruby-driver/CVE-2026-88030.yml Outdated
Comment thread gems/mongo-ruby-driver/CVE-2026-88030.yml Outdated
Comment thread gems/mongo-ruby-driver/CVE-2026-88030.yml Outdated
Comment thread rubies/mruby/CVE-2026-79590.yml Outdated
@jasnow
jasnow removed the request for review from simi September 13, 2026 18:29
@jasnow

jasnow commented Sep 13, 2026

Copy link
Copy Markdown
Member Author

ready for review

Comment thread gems/mongo/CVE-2026-88030.yml
Comment thread rubies/mruby/CVE-2026-79590.yml
@jasnow
jasnow merged commit f08b5bf into rubysec:master Sep 13, 2026
2 checks passed
@jasnow
jasnow deleted the sep-11-advs branch September 13, 2026 23:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants