SUSE alert openSUSE-SU-2026:10286-1 (ruby4.0-rubygem-rack)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:10286-1: moderate: ruby4.0-rubygem-rack-2.2-2.2.22-1.1 on GA media | |
| Date: | Thu, 05 Mar 2026 17:37:48 +0100 | |
| Message-ID: | <20260305163748.92B50FCE1@maintenance.suse.de> | |
| Archive-link: | Article |
# ruby4.0-rubygem-rack-2.2-2.2.22-1.1 on GA media Announcement ID: openSUSE-SU-2026:10286-1 Rating: moderate Cross-References: * CVE-2013-0262 * CVE-2013-0263 * CVE-2015-3225 * CVE-2018-16471 * CVE-2019-16782 * CVE-2020-8184 * CVE-2022-30122 * CVE-2022-30123 * CVE-2022-44570 * CVE-2022-44571 * CVE-2022-44572 * CVE-2023-27530 * CVE-2023-27539 * CVE-2024-25126 * CVE-2024-26141 * CVE-2024-26146 * CVE-2025-25184 * CVE-2025-27111 * CVE-2025-27610 * CVE-2025-46727 * CVE-2025-59830 * CVE-2025-61770 * CVE-2025-61771 * CVE-2025-61772 * CVE-2025-61919 * CVE-2026-22860 * CVE-2026-25500 CVSS scores: * CVE-2018-16471 ( SUSE ): 6.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2019-16782 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2020-8184 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2022-30122 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2022-30123 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-44570 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-44571 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-44572 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-27530 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-27539 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-25126 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-26141 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-26146 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-25184 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-25184 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-27111 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-27111 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-27610 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-27610 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-46727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-46727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59830 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61770 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61770 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-61771 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61771 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-61772 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61772 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-61919 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61919 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-22860 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22860 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-25500 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25500 ( SUSE ): 4.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 27 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the ruby4.0-rubygem-rack-2.2-2.2.22-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ruby4.0-rubygem-rack-2.2 2.2.22-1.1 ## References: * https://www.suse.com/security/cve/CVE-2013-0262.html * https://www.suse.com/security/cve/CVE-2013-0263.html * https://www.suse.com/security/cve/CVE-2015-3225.html * https://www.suse.com/security/cve/CVE-2018-16471.html * https://www.suse.com/security/cve/CVE-2019-16782.html * https://www.suse.com/security/cve/CVE-2020-8184.html * https://www.suse.com/security/cve/CVE-2022-30122.html * https://www.suse.com/security/cve/CVE-2022-30123.html * https://www.suse.com/security/cve/CVE-2022-44570.html * https://www.suse.com/security/cve/CVE-2022-44571.html * https://www.suse.com/security/cve/CVE-2022-44572.html * https://www.suse.com/security/cve/CVE-2023-27530.html * https://www.suse.com/security/cve/CVE-2023-27539.html * https://www.suse.com/security/cve/CVE-2024-25126.html * https://www.suse.com/security/cve/CVE-2024-26141.html * https://www.suse.com/security/cve/CVE-2024-26146.html * https://www.suse.com/security/cve/CVE-2025-25184.html * https://www.suse.com/security/cve/CVE-2025-27111.html * https://www.suse.com/security/cve/CVE-2025-27610.html * https://www.suse.com/security/cve/CVE-2025-46727.html * https://www.suse.com/security/cve/CVE-2025-59830.html * https://www.suse.com/security/cve/CVE-2025-61770.html * https://www.suse.com/security/cve/CVE-2025-61771.html * https://www.suse.com/security/cve/CVE-2025-61772.html * https://www.suse.com/security/cve/CVE-2025-61919.html * https://www.suse.com/security/cve/CVE-2026-22860.html * https://www.suse.com/security/cve/CVE-2026-25500.html
