Skip to content

Update faraday CVE-2026-54297 for 1.10.6 backport#1144

Open
wlads wants to merge 1 commit into
rubysec:masterfrom
wlads:update-98m9-hrrm-r99r
Open

Update faraday CVE-2026-54297 for 1.10.6 backport#1144
wlads wants to merge 1 commit into
rubysec:masterfrom
wlads:update-98m9-hrrm-r99r

Conversation

@wlads

@wlads wlads commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

The fix for GHSA-98m9-hrrm-r99r was backported to the 1.x branch in faraday 1.10.6, which adds a param_depth_limit to NestedParamsEncoder.

This updates the advisory accordingly:

  • Add ~> 1.10.6 to patched_versions (alongside the existing >= 2.14.3)
  • Note the backport in the description and notes
  • Add related URLs for the v1.10.6 release

Follow-up to #1136.

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants