Skip to content

Commit 7a92ea8

Browse files
authored
Merge pull request #23612 from kbrock/CVE-2025-61772
Update rack for CVE-2025-61772
2 parents 01dbb53 + fd2666e commit 7a92ea8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

Gemfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ gem "pg-dsn_parser", "~>0.1.1", :require => false
6767
gem "prism", ">=0.25.0", :require => false # Used by DescendantLoader
6868
gem "psych", ">=3.1", :require => false # 3.1 safe_load changed positional to kwargs like aliases: true: https://github.com/ruby/psych/commit/4d4439d6d0adfcbd211ea295779315f1baa7dadd
6969
gem "query_relation", "~>0.1.0", :require => false
70-
gem "rack", ">=2.2.18", :require => false # CVE-2025-59830 https://github.com/advisories/GHSA-625h-95r8-8xpm
70+
gem "rack", ">=2.2.19", :require => false # CVE-2025-61772 https://github.com/rack/rack/security/advisories/GHSA-wpv5-97wm-hp9c
7171
gem "rack-attack", "~>6.5.0", :require => false
7272
gem "rails", "~>7.2.0", ">= 7.2.2.1"
7373
gem "rails-i18n", "~>7.x"

0 commit comments

Comments
 (0)