CVE-2023-28755
published 2023-03-31CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.64%
83.9th percentile
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jruby | < jruby 9.4.5.0+ds-1 (forky) | jruby 9.4.5.0+ds-1 (forky) |
| debian | jruby | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | ruby2.7 | < jruby 9.4.5.0+ds-1 (forky) | jruby 9.4.5.0+ds-1 (forky) |
| debian | ruby2.7 | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | ruby3.1 | < jruby 9.4.5.0+ds-1 (forky) | jruby 9.4.5.0+ds-1 (forky) |
| debian | ruby3.1 | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | rubygems | < jruby 9.4.5.0+ds-1 (forky) | jruby 9.4.5.0+ds-1 (forky) |
| debian | rubygems | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jruby | jruby | >= 0 < 9.4.5.0+ds-1 | 9.4.5.0+ds-1 |
| jruby | jruby | >= 0 < 9.4.5.0+ds-1 | 9.4.5.0+ds-1 |
| msrc | cbl2_ruby_3.1.4-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| ruby-lang | uri | < 0.10.3 | 0.10.3 |
| ruby-lang | uri | <= 0.10.0 | — |
| ruby-lang | uri | — | — |
| ruby-lang | uri | — | — |
| ruby-lang | uri | — | — |
| ruby-lang | uri | >= 0 < 0.10.0.3 | 0.10.0.3 |
| ruby-lang | uri | >= 0 < 0.10.0.1 | 0.10.0.1 |
| ruby-lang | uri | >= 0.10.1 < 0.10.3 | 0.10.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RubyGems vulnerabilities
vendor_ubuntu·2025-09-03·CVSS 5.3
CVE-2025-24294 [MEDIUM] RubyGems vulnerabilities
Title: RubyGems vulnerabilities
Summary: Several security issues were fixed in RubyGems.
It was discovered that RubyGems incorrectly handled certain regular
expressions. An attacker could use this issue to cause RubyGems to crash,
resulting in a denial of service. This issue only affected Ubuntu 22.04
LTS. (CVE-2023-28755)
It was discovered that RubyGems incorrectly handled decompressed domain
names within a DNS packet. An attacker could use this issue to cause
RubyGems to crash, resulting in a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-24294)
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2023-07-12·CVSS 5.3
CVE-2023-36617 [MEDIUM] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 20.10 and Ubuntu 20.04 LTS.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue exists because of an incomplete fix for CVE-2023-28755.
(CVE-2023-36617)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
vendor_redhat·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] CWE-185 rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This issue may result in a regular expression denial of service (ReDoS).
Statement: This vulnerability exists due to an incomplete fix for CVE-2023-28755 in up
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2023-06-21·CVSS 8.8
CVE-2023-28755 [HIGH] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
Hiroshi Tokumaru discovered that Ruby did not properly handle certain
user input for applications the generate HTTP responses using cgi gem.
An attacker could possibly use this issue to maliciously modify the
response a user would receive from a vulnerable application. This issue
only affected Ubuntu 22.10. (CVE-2021-33621)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755, CVE-2023-28756)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strin
vendor_msrc·2023-06-13·CVSS 5.3
CVE-2023-36617 [MEDIUM] CWE-1333 A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strin
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in t
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2023-05-18·CVSS 5.3
CVE-2023-28756 [MEDIUM] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possily use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 ESM. (CVE-2023-28756)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ruby regression
vendor_ubuntu·2023-05-05·CVSS 5.3
CVE-2023-28755 [MEDIUM] Ruby regression
Title: Ruby regression
Summary: USN-6055-1 introduced a regression.
USN-6055-1 fixed a vulnerability in Ruby. Unfortunately it introduced a regression.
This update reverts the patches applied to CVE-2023-28755 in order to fix the regression
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2023-05-04·CVSS 5.3
CVE-2023-28755 [MEDIUM] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue is being addressed only for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2023-28756)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ruby: ReDoS vulnerability in URI
vendor_redhat·2023-03-21·CVSS 5.3
CVE-2023-28755 [MEDIUM] CWE-20 ruby: ReDoS vulnerability in URI
ruby: ReDoS vulnerability in URI
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This may result in a regular expression denial of service (ReDoS).
Package: ruby (Red Hat Enterprise Linux 6) - Out of support scope
Package: ruby (Red Hat Enterprise Linux 7) - Out of support scope
Package: ruby:2.6/ruby (Red Hat Enterprise Linux 8) - Will not fix
Package: rh-ruby30-
Debian
CVE-2023-28755: jruby - A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through...
vendor_debian·2023·CVSS 5.3
CVE-2023-28755 [MEDIUM] CVE-2023-28755: jruby - A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through...
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Scope: local
bookworm: open
forky: resolved (fixed in 9.4.5.0+ds-1)
sid: resolved (fixed in 9.4.5.0+ds-1)
trixie: resolved (fixed in 9.4.5.0+ds-1)
Debian
CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR...
vendor_debian·2023·CVSS 5.3
CVE-2023-36617 [MEDIUM] CVE-2023-36617: jruby - A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The UR...
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
rubygems vulnerabilities
osv·2025-09-03·CVSS 5.3
CVE-2023-28755 [MEDIUM] rubygems vulnerabilities
rubygems vulnerabilities
It was discovered that RubyGems incorrectly handled certain regular
expressions. An attacker could use this issue to cause RubyGems to crash,
resulting in a denial of service. This issue only affected Ubuntu 22.04
LTS. (CVE-2023-28755)
It was discovered that RubyGems incorrectly handled decompressed domain
names within a DNS packet. An attacker could use this issue to cause
RubyGems to crash, resulting in a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-24294)
OSV
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.1 vulnerabilities
osv·2023-07-12·CVSS 5.3
CVE-2023-28755 [MEDIUM] ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.1 vulnerabilities
ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.1 vulnerabilities
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 20.10 and Ubuntu 20.04 LTS.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue exists because of an incomplete fix for CVE-2023-28755.
(CVE-2023-36617)
OSV
URI gem has ReDoS vulnerability
osv·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] URI gem has ReDoS vulnerability
URI gem has ReDoS vulnerability
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with `rfc2396_parser.rb` and `rfc3986_parser.rb`.
NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
[The Ruby advisory recommends](https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/) updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
- For Ruby 3.0: Update to uri 0.10.3
- For Ruby 3.1 and 3.2: Update to uri 0.12.2.
You can use gem update uri to update it. If you
OSV
CVE-2023-36617: A ReDoS issue was discovered in the URI component before 0
osv·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] CVE-2023-36617: A ReDoS issue was discovered in the URI component before 0
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
GHSA
URI gem has ReDoS vulnerability
ghsa·2023-06-29·CVSS 5.3
CVE-2023-36617 [MEDIUM] CWE-1333 URI gem has ReDoS vulnerability
URI gem has ReDoS vulnerability
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with `rfc2396_parser.rb` and `rfc3986_parser.rb`.
NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
[The Ruby advisory recommends](https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/) updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
- For Ruby 3.0: Update to uri 0.10.3
- For Ruby 3.1 and 3.2: Update to uri 0.12.2.
You can use gem update uri to update it. If you
OSV
ruby2.3, ruby2.5, ruby2.7 vulnerabilities
osv·2023-05-18·CVSS 5.3
CVE-2023-28755 [MEDIUM] ruby2.3, ruby2.5, ruby2.7 vulnerabilities
ruby2.3, ruby2.5, ruby2.7 vulnerabilities
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possily use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 ESM. (CVE-2023-28756)
OSV
ruby2.3, ruby2.5, ruby2.7 regression
osv·2023-05-05·CVSS 5.3
CVE-2023-28755 [MEDIUM] ruby2.3, ruby2.5, ruby2.7 regression
ruby2.3, ruby2.5, ruby2.7 regression
USN-6055-1 fixed a vulnerability in Ruby. Unfortunately it introduced a regression.
This update reverts the patches applied to CVE-2023-28755 in order to fix the regression
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)
OSV
ruby2.3, ruby2.5, ruby2.7 vulnerabilities
osv·2023-05-04·CVSS 5.3
CVE-2023-28755 [MEDIUM] ruby2.3, ruby2.5, ruby2.7 vulnerabilities
ruby2.3, ruby2.5, ruby2.7 vulnerabilities
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)
It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue is being addressed only for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2023-28756)
OSV
CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0
osv·2023-03-31·CVSS 5.3
CVE-2023-28755 [MEDIUM] CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
OSV
Ruby URI component ReDoS issue
osv·2023-03-31
CVE-2023-28755 [HIGH] Ruby URI component ReDoS issue
Ruby URI component ReDoS issue
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
GHSA
Ruby URI component ReDoS issue
ghsa·2023-03-31
CVE-2023-28755 [HIGH] CWE-1333 Ruby URI component ReDoS issue
Ruby URI component ReDoS issue
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2023-28755: ReDoS vulnerability in URI
hackerone·2023-04-26·CVSS 5.3
CVE-2023-28755 [MEDIUM] CVE-2023-28755: ReDoS vulnerability in URI
CVE-2023-28755: ReDoS vulnerability in URI
Original report on the Ruby program: https://hackerone.com/reports/1444501
Advisort: https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/
NIST entry: https://nvd.nist.gov/vuln/detail/CVE-2023-28755
CVSS: 7.5 high `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` as listed by NIST but frankly I disagree with the `UI:N` part, I won't mind the extra 2k if you go with NIST but it didn't feel right not to mention it :) I filed the report with the CVSS I think this should have
Copy of the original report:
## Summary
Hello team, I hope you're doing well! The `URI` parser mishandles invalid URLs that have two `#` characters. It does correctly identify that they're invalid, but the regex performs very poorly and execution time grows m
Bugzilla
CVE-2023-29469 libxml2: Hashing of empty dict strings isn't deterministic
bugzilla·2023-04-11·CVSS 5.3
CVE-2023-29469 [MEDIUM] CVE-2023-29469 libxml2: Hashing of empty dict strings isn't deterministic
CVE-2023-29469 libxml2: Hashing of empty dict strings isn't deterministic
When hashing empty strings which aren't null-terminated, xmlDictComputeFastKey could produce inconsistent results. This could lead to various logic or memory errors, including double frees.
References:
https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4
https://gitlab.gnome.org/GNOME/libxml2/-/commit/09a2dd453007f9c7205274623acdd73747c22d64
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 2185985]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 2185987]
Created pcem tracking bugs for this issue:
Affects: fedora-all [bug 2185988]
Created qt5-qtwebengine tracking bugs for this issue:
Affects: epel-all [bug 2185986]
Affects: fedora-a
https://github.com/ruby/uri/releases/https://lists.debian.org/debian-lts-announce/2023/04/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/https://security.gentoo.org/glsa/202401-27https://security.netapp.com/advisory/ntap-20230526-0003/https://www.ruby-lang.org/en/downloads/releases/https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/https://github.com/ruby/uri/releases/https://lists.debian.org/debian-lts-announce/2023/04/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2025/05/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QA6XUKUY7B5OLNQBLHOT43UW7C5NIOQQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/https://lists.fedoraproject.org/archives/list/[email protected]/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://security.gentoo.org/glsa/202401-27https://security.netapp.com/advisory/ntap-20230526-0003/https://www.ruby-lang.org/en/downloads/releases/https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/
2023-03-31
Published