Skip to content

chore(deps): update dependency rubyzip to v3 [security] - #638

Open
renovate[bot] wants to merge 1 commit into
stagingfrom
renovate/rubygems-rubyzip-vulnerability
Open

renovate[bot] wants to merge 1 commit into
stagingfrom
renovate/rubygems-rubyzip-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
rubyzip (changelog) '~> 2.4', '>= 2.4.1' → '~> 3.0', '>= 3.4.0' age confidence

rubyzip path traversal vulnerability

CVE-2026-85396 / GHSA-47m2-wp7j-p9vc

More information

Details

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

rubyzip/rubyzip (rubyzip)

v3.4.0

Compare Source

  • Prevent entries from being extracted outside specified directory. #​664. Thanks to @​connorshea for additional reporting on this.
  • Use SecureRandom in place of insecure Random.
  • Stop reading the central directory on first error.
  • Add a check on number of declared entries in a zip file. Thanks to @​connorshea for reporting this.
  • Add note to README re reporting security issues privately.
  • Add lib/rubyzip.rb for Bundler auto-require. #​660

Tooling/internal:

  • Replace the test Excel spreadsheet fixture.
  • Use assert_silent shorthand when expecting no output from a test.
  • Clean up CentralDirectory instance variables.
  • Add Ruby 4.0 to the Windows CI and update CI matrix in the README.
  • List ZIP docs that we store here and link to online versions. #​657

v3.3.1

Compare Source

  • Reinstate default param for InputStream#sysread. #​663

v3.3.0

Compare Source

  • Refactor InputStream and AbstractInputStream.
    #​661

Tooling/internal:

  • Update Actions to use checkout@​v5.
  • Add Ruby4.0 to the CI matrix. #​659

v3.2.2

Compare Source

  • Fix reading EOCDs when header signatures are in an Entry payload. #​656

Tooling/internal:

  • Stop using macos-13 runners in GitHub Actions.
  • Update YJIT GitHub Actions runners.

v3.2.1

Compare Source

  • Fix Entry#gather_fileinfo_from_srcpath error messages. #​654

Tooling/internal:

  • Add some simple benchmarks for reading the cdir.

v3.2.0

Compare Source

Tooling/internal:

  • Entry: clean up reading and writing the Central Directory headers.
  • Improve Zip64 tests for OutputStream.
  • Extra fields: use symbols as indices as opposed to strings.
  • Ensure that Unknown extra field has a superclass.

v3.1.1

Compare Source

  • Improve the IO pipeline when decompressing. #​649 (which also fixes #​647)

Tooling/internal:

  • Improve the DecryptedIo class with various updates and optimizations.
  • Remove the NullDecrypter class.
  • Properly convert the test suite to use minitest.
  • Move all test helper code into separate files.
  • Updates to the Actions CI, including new OS versions.
  • Update rubocop versions and fix resultant cop failures. #​646

v3.1.0

Compare Source

Tooling/internal:

  • Add various useful zip specification documents to the repo for ease of finding them in the future. These are not included in the gem release.

v3.0.2

Compare Source

  • Fix InputStream#sysread to handle frozen string literals. #​643
  • Ensure that we don't flush too often when deflating. #​322
  • Stop print causing Zlib errors. #​642
  • Ensure that print and printf return nil.

v3.0.1

Compare Source

  • Restore Zip::File's Enumerable status. #​641
  • Escape filename pattern when matching in Entry#name_safe?. #​639
  • Eagerly require gem version. #​637
  • Fix direct require of Entry by requiring constants. #​636

v3.0.0

Compare Source

  • Fix de facto regression for input streams.
  • Fix File#write_buffer to always return the given io.
  • Add Entry#absolute_time? and DOSTime#absolute_time? methods.
  • Use explicit named parameters for File methods.
  • Ensure that entries can be extracted safely without path traversal. #​540
  • Enable Zip64 by default.
  • Rename GPFBit3Error to StreamingError.
  • Ensure that Entry.ftype is correct via InputStream. #​533
  • Add Entry#zip64? as a better way detect Zip64 entries.
  • Implement Zip::FileSystem::ZipFsFile#symlink?.
  • Remove File::add_buffer from the API.
  • Fix OutputStream#put_next_entry to preserve StreamableStreams. #​503
  • Ensure File.open_buffer doesn't rewrite unchanged data.
  • Add CentralDirectory#count_entries and File::count_entries.
  • Fix reading unknown extra fields. #​505
  • Fix reading zip files with max length file comment. #​508
  • Fix reading zip64 files with max length file comment. #​509
  • Don't silently alter zip files opened with Zip::sort_entries. #​329
  • Use named parameters for optional arguments in the public API.
  • Raise an error if entry names exceed 65,535 characters. #​247
  • Remove the ZipXError v1 legacy classes.
  • Raise an error on reading a split archive with InputStream. #​349
  • Ensure InputStream raises GPFBit3Error for OSX Archive files. #​493
  • Improve documentation and error messages for InputStream. #​196
  • Fix zip file-level comment is not read from zip64 files. #​492
  • Fix Zip::OutputStream.write_buffer doesn't work with Tempfiles. #​265
  • Reinstate normalising pathname separators to /. #​487
  • Fix restore options consistency. #​486
  • View and/or preserve original date created, date modified? (Windows). #​336
  • Fix frozen string literal error. #​475
  • Set the default Entry time to the file's mtime on Windows. #​465
  • Ensure that Entry#time= sets times as DOSTime objects. #​481
  • Replace and deprecate Zip::DOSTime#dos_equals. #​464
  • Fix loading extra fields. #​459
  • Set compression level on a per-zipfile basis. #​448
  • Fix input stream partial read error. #​462
  • Fix zlib deflate buffer growth. #​447

Tooling/internal:

  • No longer test setting $\ in tests.
  • Add a test to ensure correct version number format.
  • Update the README with new Ruby version compatability information.
  • Fix various issues with JRuby tests.
  • Update gem dependency versions.
  • Add Ruby 3.4 to the CI.
  • Fix mispelled variable names in the crypto classes.
  • Only use the Zip64 CDIR end locator if needed.
  • Prevent unnecessary Zip64 data being stored.
  • Abstract marking various things as 'dirty' into Dirtyable for reuse.
  • Properly test File#mkdir.
  • Remove unused private method File#directory?.
  • Expose the EntrySet more cleanly through CentralDirectory.
  • Zip::File no longer subclasses Zip::CentralDirectory.
  • Configure Coveralls to not report a failure on minor decreases of test coverage. #​491
  • Extract the file splitting code out into its own module.
  • Refactor, and tidy up, the Zip::Filesystem classes for improved maintainability.
  • Fix Windows tests. #​489
  • Refactor assert_forwarded so it does not need ObjectSpace._id2ref or eval. #​483
  • Add GitHub Actions CI infrastructure. #​469
  • Add Ruby 3.0 to CI. #​474
  • Fix the compression level tests to compare relative sizes. #​473
  • Simplify assertions in basic_zip_file_test. #​470
  • Remove compare_enumerables from test_helper.rb. #​468
  • Use correct SPDX license identifier. #​458
  • Enable truffle ruby in Travis CI. #​450
  • Update rubocop again and run it in CI. #​444
  • Fix a test that was incorrect on big-endian architectures. #​445

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 26, 2026
@renovate

renovate Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Gemfile.lock
Writing lockfile to /tmp/renovate/repos/github/csvalpha/amber-api/Gemfile.lock
Fetching gem metadata from https://rubygems.org/........
Resolving dependencies...

Could not find compatible versions

Because roo >= 2.8.3, < 3.0.0 depends on rubyzip >= 1.3.0, < 3.0.0
  and Gemfile depends on roo >= 2.10.1, < 3.A,
  rubyzip >= 1.3.0, < 3.0.0 is required.
So, because Gemfile depends on rubyzip >= 3.4.0, < 4.A,
  version solving has failed.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a12b9b84-7d6b-4cdd-9e27-ddef86f292eb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants