Skip to content

GHSA SYNC: 1 brand new jwt advisory#1057

Open
wlads wants to merge 2 commits into
rubysec:masterfrom
wlads:ghsa-syncbot-jwt-2026-05-19
Open

GHSA SYNC: 1 brand new jwt advisory#1057
wlads wants to merge 2 commits into
rubysec:masterfrom
wlads:ghsa-syncbot-jwt-2026-05-19

Conversation

@wlads
Copy link
Copy Markdown
Contributor

@wlads wlads commented May 19, 2026

GHSA SYNC: 1 brand new jwt advisory

Copy link
Copy Markdown
Contributor

@jasnow jasnow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. Per CONTRIBUTING.md, please wrap text fields at 80 columns.
  2. CVE not in the NVD database. Please add "https://www.cve.org/CVERecord?id=CVE-2026-45363" to RELATED/URL field. Note that the CVE is reserved and empty.
    Thanks for your contribution.

@wlads wlads force-pushed the ghsa-syncbot-jwt-2026-05-19 branch from 74e417f to 234d664 Compare May 19, 2026 20:54
@wlads
Copy link
Copy Markdown
Contributor Author

wlads commented May 19, 2026

Thanks for the review @jasnow! Just pushed the requested changes — ready for another look when you get a chance 🙂

jasnow

This comment was marked as outdated.

- ">= 3.2.0"
related:
url:
- https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OK to remove the duplicate @jasnow?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what duplicate?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

seems none, it is in root url and here also which is intended 💪

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm confused. Think I need more words to describe the original feedback.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is ok to just ignore it. I wasn't sure if root url and related urls can overlap.

- https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
- https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f
- https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0
- https://github.com/advisories/GHSA-c32j-vqhx-rx3x
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it worth to keep this url also? It is almost the same page as the main url.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there really any value in keeping both links?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I also collect URLs and put them in the related: / url: field then pick an advisory URL to use in the url: field.
Never thought of it as duplicates and @postmodern asked for it.

---
gem: jwt
cve: 2026-45363
notes: 'CVE has been reserved, but not filled in.'
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants