Skip to content

2.10.31

@eduardoj eduardoj tagged this 10 Mar 17:29
Bugfixes
========

Frontend:
 * Update rack RubyGem to version 2.2.22
   - XSS injection via malicious filename in Rack::Directory (CVE-2026-25500)
   - Directory traversal via root prefix bypass in Rack::Directory (CVE-2026-22860)
Assets 2
Loading