From 0d6d06a0787539c7736c4c4cba9102a5e528c1c9 Mon Sep 17 00:00:00 2001 From: Alex Leasenco Date: Fri, 26 Dec 2025 14:04:09 +0200 Subject: [PATCH] Update rexml from 3.2.5 to 3.4.4 Security update for rexml gem (transitive dependency via crack/webmock). Includes fixes for DoS vulnerabilities https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946/ and improved XML parsing strictness. --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index ad743664..487e84a4 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -33,7 +33,7 @@ GEM rake (12.3.3) rake-release (1.3.0) bundler (>= 1.11, < 3) - rexml (3.2.5) + rexml (3.4.4) rspec (3.12.0) rspec-core (~> 3.12.0) rspec-expectations (~> 3.12.0)