Skip to content

Update addressable to 2.9.0 (CVE-2026-35611) - #1258

Merged
iangmaia merged 1 commit into
trunkfrom
iangmaia/update-addressable-2.9.0
Apr 8, 2026
Merged

Update addressable to 2.9.0 (CVE-2026-35611)#1258
iangmaia merged 1 commit into
trunkfrom
iangmaia/update-addressable-2.9.0

Conversation

@iangmaia

@iangmaia iangmaia commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

Fixes AINFRA-2264

Summary

  • Bumps addressable gem from vulnerable version to 2.9.0
  • Fixes CVE-2026-35611 (GHSA-h27x-rffw-24p4) — high severity ReDoS in Addressable templates
  • Vulnerable range: >= 2.3.0, < 2.9.0

Test plan

  • CI passes
  • No changes to app behavior (transitive dependency only)

🤖 Generated with Claude Code

Bumps the addressable gem to 2.9.0 to resolve a high severity
Regular Expression Denial of Service (ReDoS) vulnerability in
Addressable templates (GHSA-h27x-rffw-24p4).

Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
@dangermattic

dangermattic commented Apr 8, 2026

Copy link
Copy Markdown
Collaborator
1 Warning
⚠️ PR is not assigned to a milestone.

Generated by 🚫 Danger

@iangmaia
iangmaia requested review from mokagio and twstokes April 8, 2026 13:10
@iangmaia iangmaia self-assigned this Apr 8, 2026
@iangmaia iangmaia added the tooling Related to anything that supports the building & maintaining of the project. label Apr 8, 2026
@iangmaia
iangmaia merged commit a103678 into trunk Apr 8, 2026
9 of 10 checks passed
@iangmaia
iangmaia deleted the iangmaia/update-addressable-2.9.0 branch April 8, 2026 17:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tooling Related to anything that supports the building & maintaining of the project.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants