Skip to content

One new dalli advisory (GHSA-6wmv-xq9m-fmp7) - #1247

Merged
jasnow merged 2 commits into
rubysec:masterfrom
petergoldstein:dalli-GHSA-6wmv-xq9m-fmp7
Sep 27, 2026
Merged

jasnow merged 2 commits into
rubysec:masterfrom
petergoldstein:dalli-GHSA-6wmv-xq9m-fmp7

Conversation

@petergoldstein

Copy link
Copy Markdown
Contributor

Adds GHSA-6wmv-xq9m-fmp7 for dalli, submitted by the dalli maintainer.

Advisory: GHSA-6wmv-xq9m-fmp7

Summary: memcached command injection. The default argument of Dalli::Client#incr/#decr, and fetch_with_lock's lock_ttl/recache_threshold, were written into meta protocol commands without integer conversion, so a String containing CRLF injected additional memcached commands.

Versions

  • Affected: 3.2.0–3.2.8, 4.0.0–4.3.3, 5.0.0–5.0.6 and 5.1.0. In 3.2.x and 4.x, only clients using protocol: :meta are affected.
  • Patched: 3.2.9, 4.3.4, 5.0.7 and 5.1.1, expressed as ~> 3.2.9, ~> 4.3.4, ~> 5.0.7 and >= 5.1.1.

Notes

  • A CVE has been requested through GitHub but not yet assigned, so the entry has no cve: field. I'll follow up with it once it's assigned.
  • bundle exec rspec spec/advisories_spec.rb spec/schema_validation_spec.rb passes locally.

🤖 Generated with Claude Code

Memcached command injection through numeric arguments to incr/decr and
fetch_with_lock. Fixed in 3.2.9, 4.3.4, 5.0.7 and 5.1.1.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add this to the bottom of file:

    - https://rubygems.org/gems/dalli/versions/5.1.1
    - https://github.com/petergoldstein/dalli/releases/tag/v5.1.1
    - https://rubygems.org/gems/dalli/versions/5.0.7
    - https://github.com/petergoldstein/dalli/releases/tag/v5.0.7
    - https://rubygems.org/gems/dalli/versions/4.3.4
    - https://github.com/petergoldstein/dalli/releases/tag/v4.3.4
notes: |
  - No CVE in GHSA.
     - "A CVE has been requested through GitHub but not yet
        assigned, so the  entry has no cve: field."
  - cvss_v3 from GHSA URL.

@jasnow

jasnow commented Sep 25, 2026

Copy link
Copy Markdown
Member

PS. Thanks for you contribution.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@petergoldstein

Copy link
Copy Markdown
Contributor Author

Thanks for the review! Added the release and RubyGems links and the notes: block as requested.

I also added the two 3.2.9 links, since 3.2.9 is one of the four patched versions (~> 3.2.9) and I think it was just left out of the list. Specs still pass locally, and all ten related URLs resolve.

I'll follow up with the cve: field once GitHub assigns it.

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jasnow
jasnow requested a review from simi September 25, 2026 17:11
@jasnow
jasnow merged commit 0e150d5 into rubysec:master Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants