Skip to content

Commit 15cd364

Browse files
Update faraday gem version constraint in Gemfile and Gemfile.lock to prevent upgrades beyond 3.0, addressing CVE-2026-25765 (SSRF vulnerability).
1 parent 9aeab44 commit 15cd364

File tree

2 files changed

+3
-2
lines changed

2 files changed

+3
-2
lines changed

Gemfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -92,7 +92,7 @@ gem 'dotenv-rails', groups: %i[development test]
9292
gem 'httparty', '>= 0.24.0'
9393

9494
# Security: Fix CVE-2026-25765 (SSRF vulnerability)
95-
gem 'faraday', '>= 2.14.1'
95+
gem 'faraday', '>= 2.14.1', '< 3.0'
9696

9797
# Markdown renderer
9898
gem 'redcarpet'

Gemfile.lock

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -136,7 +136,7 @@ GEM
136136
railties (>= 6.1.0)
137137
faker (3.5.2)
138138
i18n (>= 1.8.11, < 2)
139-
faraday (2.13.2)
139+
faraday (2.14.1)
140140
faraday-net_http (>= 2.0, < 3.5)
141141
json
142142
logger
@@ -550,6 +550,7 @@ DEPENDENCIES
550550
dotenv-rails
551551
factory_bot_rails
552552
faker
553+
faraday (>= 2.14.1, < 3.0)
553554
google-api-client
554555
googleauth
555556
httparty (>= 0.24.0)

0 commit comments

Comments
 (0)