Debian Package Tracker
Register | Log in
Subscribe

ruby-secure-headers

Security related headers all in one gem

Choose email to subscribe with

general
  • source: ruby-secure-headers (main)
  • version: 7.3.0-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Abhijith PA [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 6.3.2-1
  • oldstable: 6.3.2-1
  • stable: 6.3.2-2
  • testing: 7.3.0-1
  • unstable: 7.3.0-1
versioned links
  • 6.3.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.3.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.3.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-secure-headers
action needed
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-54163: secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \r, or \n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.
Created: 2026-07-18 Last update: 2026-09-01 22:00
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-54163: secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \r, or \n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.
Created: 2026-07-18 Last update: 2026-08-02 20:32
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-54163: (needs triaging) secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \r, or \n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-07-18 Last update: 2026-09-01 22:00
news
[rss feed]
  • [2026-06-22] ruby-secure-headers 7.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-15] Accepted ruby-secure-headers 7.3.0-1 (source) into unstable (Simon Quigley)
  • [2026-03-01] ruby-secure-headers 7.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-23] Accepted ruby-secure-headers 7.2.0-1 (source) into unstable (Simon Quigley)
  • [2025-10-28] ruby-secure-headers 7.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-22] Accepted ruby-secure-headers 7.1.0-1 (source) into unstable (Simon Quigley)
  • [2023-11-27] ruby-secure-headers 6.3.2-2 MIGRATED to testing (Debian testing watch)
  • [2023-11-22] Accepted ruby-secure-headers 6.3.2-2 (source) into unstable (Abhijith PA)
  • [2021-07-16] ruby-secure-headers 6.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-06-25] Accepted ruby-secure-headers 6.3.2-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-10-09] Accepted ruby-secure-headers 6.3.1-1~bpo10+1 (source all) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
  • [2020-08-28] ruby-secure-headers 6.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-08-26] Accepted ruby-secure-headers 6.3.1-1 (source) into unstable (Cédric Boutillier)
  • [2019-10-27] ruby-secure-headers 6.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-10-24] Accepted ruby-secure-headers 6.1.1-1 (source) into unstable (Samyak Jain) (signed by: Praveen Arimbrathodiyil)
  • [2018-12-29] ruby-secure-headers 6.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2018-12-27] Accepted ruby-secure-headers 6.0.0-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-07-28] ruby-secure-headers 5.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2018-07-25] Accepted ruby-secure-headers 5.0.5-1 (source) into unstable (Kannan V M) (signed by: Praveen Arimbrathodiyil)
  • [2017-09-21] ruby-secure-headers 3.7.1-1 MIGRATED to testing (Debian testing watch)
  • [2017-09-15] Accepted ruby-secure-headers 3.7.1-1 (source) into unstable (Sruthi Chandran) (signed by: Praveen Arimbrathodiyil)
  • [2017-09-07] ruby-secure-headers 3.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2017-09-02] Accepted ruby-secure-headers 3.5.0-1 (source all) into unstable, unstable (Abhijith PA) (signed by: Praveen Arimbrathodiyil)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 7.3.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing