Skip to content

Update vendored cgi gem #8919

@donoghuc

Description

@donoghuc

The vendored (default) cgi gem

['cgi', '0.4.1'],
has a reported CVE https://nvd.nist.gov/vuln/detail/CVE-2025-27220.

Several patched releases of cgi are available https://rubygems.org/gems/cgi/versions. It looks like MRI ruby is going with 0.4.2 https://stdgems.org/. Perhaps that is the best path?

In general what is the strategy for default gems in jruby? Are they meant to track a specific ruby major/minor?

For example in the jruby 9.4 stream would the default gems track those in ruby 3.1? Or ruby 3.y?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions