Ruby 4.0.3 has been released as a security patch containing ERB 6.0.1.1, which fixes CVE-2026-41316. Applications that call Marshal.load on untrusted data while having both erb and activesupport loaded are affected and should update. The release schedule for upcoming Ruby 4.0 patch versions is also outlined, with 4.0.4 planned for May.
Sort: