Security advisories: CVE-2025-27219, CVE-2025-27220 and CVE-2025-27221 We published security advisories for CVE-2025-27219, CVE-2025-27220 and CVE-2025-27221. Please read the details below.
CVE-2025-27219: Denial of Service in CGI::Cookie.parse.
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. ...
Ruby 3.4.2 Released Ruby 3.4.2 has been released.
This is a routine update that includes bug fixes. Please refer to the
release notes on GitHub for further details.
Release Schedule
We intend to release the latest stable Ruby version (currently Ruby 3.4) every 2 months.
Ruby 3.4.3 will be released in April, 3.4.4 ...
CVE-2025-25186: DoS vulnerability in net-imap There is a possibility for DoS by in the net-imap gem. This vulnerability has been assigned the CVE identifier CVE-2025-25186. We recommend upgrading the net-imap gem.
Details
A malicious server can send highly compressed uid-set data which is automatically read by the client’s receiver ...
Ruby 3.2.7 Released Ruby 3.2.7 has been released.
Please see the GitHub releases for further details.
Download
https://cache.ruby-lang.org/pub/ruby/3.2/ruby-3.2.7.tar.gz
SIZE: 20548416
SHA1: c45aa881a7ea1175212d385fe5c8b6e9ff14b2e5
SHA256: ...
Ruby 3.3.7 Released Ruby 3.3.7 has been released.
This is a routine update that includes minor bug fixes.
Please refer to the release notes on GitHub for further details.
Download
https://cache.ruby-lang.org/pub/ruby/3.3/ruby-3.3.7.tar.gz
SIZE: 22163173
SHA1: ...
Ruby 3.4.1 Released Ruby 3.4.1 has been released.
This fixes the version description.
See the GitHub releases for further details.
Download
https://cache.ruby-lang.org/pub/ruby/3.4/ruby-3.4.1.tar.gz
SIZE: 23152739
SHA1: dc42fe22bcdfbd30f63cd93296d893c53b1dadcc
SHA256: ...
Ruby 3.4.0 Released We are pleased to announce the release of Ruby 3.4.0. Ruby 3.4 adds it block parameter reference,
changes Prism as default parser, adds Happy Eyeballs Version 2 support to socket library, improves YJIT,
adds Modular GC, and so on.
it is introduced
it is added to reference a block parameter with ...
Ruby 3.4.0 rc1 Released We are pleased to announce the release of Ruby 3.4.0-rc1.
Prism
Switch the default parser from parse.y to Prism. [Feature #20564]
Modular GC
Alternative garbage collector (GC) implementations can be loaded dynamically
through the modular garbage collector feature. To enable this ...
Ruby 3.3.6 Released Ruby 3.3.6 has been released.
This is a routine update that includes minor bug fixes.
It also stops warning missing default gem dependencies that will be bundled gems in Ruby 3.5.
For more details, please refer to the release notes on GitHub.
Release Schedule
As previously announced, we intend ...
Ruby 3.2.6 Released Ruby 3.2.6 has been released.
Please see the GitHub releases for further details.
Download
https://cache.ruby-lang.org/pub/ruby/3.2/ruby-3.2.6.tar.gz
SIZE: 20521981
SHA1: bbf265f5e7a3f480056dc2fa6d600a97cba00713
SHA256: ...