From: "hsbt (Hiroshi SHIBATA) via ruby-core" Date: 2026-04-16T01:48:53+00:00 Subject: [ruby-core:125283] [Ruby Misc#22005] Missing information about CVE on cve.org Issue #22005 has been updated by hsbt (Hiroshi SHIBATA). We recently switched our CVE Numbering Authority from MITRE to GitHub, which may be causing this. Previously, MITRE would update cve.org records on their own after we published advisories on www.ruby-lang.org, but it seems GitHub may not do the same automatically. We'll look into it, though I'm not yet sure we can fully resolve this on our end. ---------------------------------------- Misc #22005: Missing information about CVE on cve.org https://bugs.ruby-lang.org/issues/22005#change-117037 * Author: vo.x (Vit Ondruch) * Status: Open ---------------------------------------- The CVE-2026-27820 was fixed and disclosed more than one month ago: https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-27820/ However, there is still no public information on https://www.cve.org/CVERecord?id=CVE-2026-27820 . Could this be fixed please? BTW the same situation was for CVE-2025-61594, where the information was not there for months. This points to a gap in a security release process. Could the process be improved so the information is disclosed in timely manner? -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/