Debian Package Tracker
Register | Log in
Subscribe

ruby-css-parser

Ruby CSS parser library

Choose email to subscribe with

general
  • source: ruby-css-parser (main)
  • version: 3.1.0-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Lucas Kanashiro [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.6.0-1
  • oldstable: 1.6.0-2+deb12u1
  • old-p-u: 1.6.0-2+deb12u1
  • stable: 1.19.0-1+deb13u1
  • testing: 3.1.0-1
  • unstable: 3.1.0-1
versioned links
  • 1.6.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.0-2+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.19.0-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-css-parser
action needed
A new upstream version is available: 3.2.0 high
A new upstream version 3.2.0 is available, you should consider packaging it.
Created: 2026-09-21 Last update: 2026-09-23 17:48
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-53727: css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.
Created: 2026-07-18 Last update: 2026-09-15 13:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-53727: css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.
Created: 2026-07-18 Last update: 2026-09-15 13:30
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2026-53727: css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.
1 issue postponed or untriaged:
  • CVE-2026-44312: (postponed; to be fixed through a stable update) css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS certificate—even entirely untrusted—will be accepted without validation. This vulnerability is fixed in 2.1.0 and 1.22.0.
Created: 2026-07-18 Last update: 2026-08-02 20:32
news
[rss feed]
  • [2026-09-16] ruby-css-parser 3.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-11] Accepted ruby-css-parser 3.1.0-1 (source) into unstable (Simon Quigley)
  • [2026-06-24] ruby-css-parser 3.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-20] Accepted ruby-css-parser 3.0.0-1 (source) into unstable (Simon Quigley)
  • [2026-06-09] Accepted ruby-css-parser 1.6.0-2+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Aquila Macedo Costa)
  • [2026-06-09] Accepted ruby-css-parser 1.19.0-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Aquila Macedo Costa)
  • [2026-05-05] ruby-css-parser 2.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-29] Accepted ruby-css-parser 2.1.0-1 (source) into unstable (Simon Quigley)
  • [2026-03-06] ruby-css-parser 2.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-28] Accepted ruby-css-parser 2.0.0-1 (source) into unstable (Simon Quigley)
  • [2025-11-12] ruby-css-parser 1.21.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-09] Accepted ruby-css-parser 1.21.1-1 (source) into unstable (Simon Quigley)
  • [2024-09-28] ruby-css-parser 1.19.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-25] Accepted ruby-css-parser 1.19.0-1 (source) into unstable (Cédric Boutillier)
  • [2024-02-13] ruby-css-parser 1.16.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-09] Accepted ruby-css-parser 1.16.0-1 (source) into unstable (Lucas Kanashiro)
  • [2021-11-19] ruby-css-parser 1.6.0-2 MIGRATED to testing (Debian testing watch)
  • [2021-11-15] Accepted ruby-css-parser 1.6.0-2 (source) into unstable (Daniel Leidert)
  • [2017-10-04] ruby-css-parser 1.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2017-09-28] Accepted ruby-css-parser 1.6.0-1 (source) into unstable (Cédric Boutillier)
  • [2017-08-28] Accepted ruby-css-parser 1.5.0.pre2-1 (source all) into unstable (Lucas Kanashiro)
  • [2016-01-30] ruby-css-parser 1.3.6-1 MIGRATED to testing (Debian testing watch)
  • [2016-01-24] Accepted ruby-css-parser 1.3.6-1 (source all) into unstable, unstable (Antonio Terceiro)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.0.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing