Tracking issue for dependency CVEs surfaced by the Trivy scan on 2026-10-07. Scan totals: 1 critical, 3 high.
concurrent-ruby 1.3.6 -> 1.3.7 -- CVE-2026-54906 (critical, ReadWriteLock synchronization flaw allows unauthorized lock acquisition) and CVE-2026-54904 (high, DoS via infinite loop in AtomicReference#update). One bump clears both.
addressable 2.8.8 -> 2.9.0 -- CVE-2026-35611 (DoS via crafted URI templates)
faraday 2.8.1 -> 2.14.3 -- CVE-2026-54297 (DoS via crafted nested query strings)
Tracking issue for dependency CVEs surfaced by the Trivy scan on 2026-10-07. Scan totals: 1 critical, 3 high.
concurrent-ruby 1.3.6 -> 1.3.7-- CVE-2026-54906 (critical, ReadWriteLock synchronization flaw allows unauthorized lock acquisition) and CVE-2026-54904 (high, DoS via infinite loop in AtomicReference#update). One bump clears both.addressable 2.8.8 -> 2.9.0-- CVE-2026-35611 (DoS via crafted URI templates)faraday 2.8.1 -> 2.14.3-- CVE-2026-54297 (DoS via crafted nested query strings)