<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Wonder if https:&#x2F;&#x2F;www.ruby-lang.org&#x2F;en&#x2F;news&#x2F;2026&#x2F;04&#x2F;21&#x2F;erb-cve-2026-41316&#x2F; (CVE-2026-41316) is an issue for Mastodon?]]></title><description><![CDATA[<p>Wonder if <a href="https://www.ruby-lang.org/en/news/2026/04/21/erb-cve-2026-41316/" rel="nofollow noopener"><span>https://www.</span><span>ruby-lang.org/en/news/2026/04/</span><span>21/erb-cve-2026-41316/</span></a> (CVE-2026-41316) is an issue for Mastodon? </p><p>Gemfile.lock for stable-4.5 still has erb (5.1.3), but no idea if Mastodon uses it in an attackable way.</p><p><a href="https://mastodon.infra.de/tags/mastoadmin" rel="tag">#<span>mastoadmin</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/90b1d238-61e3-4eba-9d5e-8ac028a9ecae/wonder-if-https-www.ruby-lang.org-en-news-2026-04-21-erb-cve-2026-41316-cve-2026-41316-is-an-issue-for-mastodon</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 23:27:14 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/90b1d238-61e3-4eba-9d5e-8ac028a9ecae.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Apr 2026 08:18:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Wonder if https:&#x2F;&#x2F;www.ruby-lang.org&#x2F;en&#x2F;news&#x2F;2026&#x2F;04&#x2F;21&#x2F;erb-cve-2026-41316&#x2F; (CVE-2026-41316) is an issue for Mastodon? on Thu, 23 Apr 2026 11:52:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/galaxis%40mastodon.infra.de" rel="nofollow noopener">@<span>galaxis</span></a></span> mastodon code itself has no references to Marshal, as well as <code>json-ld-*</code>, <code>sidekiq</code> uses json serialization </p><p>It’s highly unlikely that dependencies use marshaling as well. It’s used to encode raw ruby objects which is very rare and subject to Ruby version incompatibility</p>]]></description><link>https://board.circlewithadot.net/post/https://feed.yopp.me/users/alex/statuses/116453876260751220</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://feed.yopp.me/users/alex/statuses/116453876260751220</guid><dc:creator><![CDATA[alex@feed.yopp.me]]></dc:creator><pubDate>Thu, 23 Apr 2026 11:52:13 GMT</pubDate></item></channel></rss>