openSUSE-SU-2026:20998-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20998-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20998-1
Upstream
CVE (2)
Related
Published
2026-06-22T07:40:16Z
Modified
2026-06-30T18:24:40Z
Summary
Security update for tree-sitter-ruby
Details

This update for tree-sitter-ruby fixes the following issues

  • CVE-2025-5889: brace-expansion: inefficient regular expression complexity in function expand of file index.js (bsc#1244345).
  • CVE-2025-59343: tar-fs: tar-fs symlink validation bypass (bsc#1250517).

Changes for tree-sitter-ruby:

  • Use correct tree-sitter dirname instead of tree_sitter (bsc#1267461).

  • update to 0.23.1:

  • ci(publish): add attestations and generate parser
  • build: update bindings
  • fix: remove unnecessary empty string usage
  • chore: regenerate
  • ci: update workflows
  • fix(swift): include scanner.c
  • update to 0.23.0:
  • fix(go): correct test
  • fix: handle != operator definition
  • feat: support element references with blocks
  • fix: do not require newline after block comment =end
  • fix: parsing of multiple unicode escapes
  • fix: correct repo url
  • update to 0.21.0:
  • feat: rewrite scanner with array header and regenerate
  • build: update bindings and manifests
  • fix: reverse precedence queries
  • fix: escape braces in regex
  • docs: update badges
  • switch to download_files service
  • add neovim links
  • add license file to package
References

Affected packages

openSUSE:Leap 16.0 / tree-sitter-ruby

Package

Name
tree-sitter-ruby
Purl
pkg:rpm/opensuse/tree-sitter-ruby&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.1-160000.3.1

Ecosystem specific

{
    "binaries": [
        {
            "tree-sitter-ruby": "0.23.1-160000.3.1",
            "tree-sitter-ruby-devel": "0.23.1-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20998-1.json"