Skip to content

Update addressable to 2.9.0 (CVE-2026-35611)#802

Merged
iangmaia merged 1 commit intotrunkfrom
iangmaia/update-addressable-2.9.0
Apr 9, 2026
Merged

Update addressable to 2.9.0 (CVE-2026-35611)#802
iangmaia merged 1 commit intotrunkfrom
iangmaia/update-addressable-2.9.0

Conversation

@iangmaia
Copy link
Copy Markdown
Contributor

@iangmaia iangmaia commented Apr 9, 2026

Fixes AINFRA-2264

Summary

  • Bumps addressable gem from vulnerable version to 2.9.0
  • Fixes CVE-2026-35611 (GHSA-h27x-rffw-24p4) — high severity ReDoS in Addressable templates
  • Vulnerable range: >= 2.3.0, < 2.9.0

Test plan

  • CI passes
  • No changes to app behavior (transitive dependency only)

🤖 Generated with Claude Code

Bumps the addressable gem to 2.9.0 to resolve a high severity
Regular Expression Denial of Service (ReDoS) vulnerability in
Addressable templates (GHSA-h27x-rffw-24p4).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@iangmaia iangmaia self-assigned this Apr 9, 2026
@iangmaia iangmaia requested review from mokagio and twstokes April 9, 2026 10:03
@wpmobilebot
Copy link
Copy Markdown

App Icon📲 You can test the changes from this Pull Request in Gravatar Prototype Build by scanning the QR code below to install the corresponding build.
App NameGravatar Prototype Build
Build Number2467
VersionPR #802
Bundle IDcom.automattic.gravatar-sdk-demo-uikit.prototype-build
Commitc64bc8a
Installation URL38rgs6cgckde0
Automatticians: You can use our internal self-serve MC tool to give yourself access to those builds if needed.

@iangmaia iangmaia merged commit 897eca1 into trunk Apr 9, 2026
9 checks passed
@iangmaia iangmaia deleted the iangmaia/update-addressable-2.9.0 branch April 9, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants