Skip to content

[GHSA-h4w6-wx8r-p68v] ruby webrick through v1.9.2 WEBrick reparses trailer... - #10212

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10212from
ranjiGT-GHSA-h4w6-wx8r-p68v
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10212from
ranjiGT-GHSA-h4w6-wx8r-p68v

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 7, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • Description
  • References
  • Source code location
  • Summary

Comments
Adds the RubyGems package mapping, affected version range, source repository, and upstream fix commit for this vulnerability.

WEBrick through version 1.9.2 is affected. The upstream commit 25b0e9206bf5991c6274893d53c428d23b3f2292 ("Only allow specific trailers") fixes ruby/webrick#198 by preventing content-length and other restricted fields from being accepted as chunked trailers and by parsing trailers separately from the canonical request headers.

The fix is not contained in any currently released tag, so no patched version is specified.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 18:40
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10212 October 7, 2026 18:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The metadata is valid and consistent with the upstream issue, merged fix, and currently released tags.

0 open findings

What changed in this PR

Updates the WEBrick advisory with accurate package, affected-version, vulnerability, and upstream remediation metadata.

Changes:

  • Adds the RubyGems webrick affected range through 1.9.2.
  • Adds a concise summary and clarified description.
  • Adds upstream repository and fix commit references.
File Description
advisories/​unreviewed/​2026/​07/​GHSA-h4w6-wx8r-p68v/​GHSA-h4w6-wx8r-p68v.json Completes the advisory’s vulnerability and package metadata.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants