From: "vo.x (Vit Ondruch) via ruby-core" Date: 2026-04-15T15:31:02+00:00 Subject: [ruby-core:125280] [Ruby Misc#22005] Missing information about CVE on cve.org Issue #22005 has been reported by vo.x (Vit Ondruch). ---------------------------------------- Misc #22005: Missing information about CVE on cve.org https://bugs.ruby-lang.org/issues/22005 * Author: vo.x (Vit Ondruch) * Status: Open ---------------------------------------- The CVE-2026-27820 was fixed and disclosed more than one month ago: https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-27820/ However, there is still no public information on https://www.cve.org/CVERecord?id=CVE-2026-27820 . Could this be fixed please? BTW the same situation was for CVE-2025-61594, where the information was not there for months. This points to a gap in a security release process. Could the process be improved so the information is disclosed in timely manner? -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/