Skip to content

Bump gixy-ng from 0.2.46 to 0.2.47#28

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/main/gixy-ng-0.2.47
Closed

Bump gixy-ng from 0.2.46 to 0.2.47#28
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/main/gixy-ng-0.2.47

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 25, 2026

Copy link
Copy Markdown
Contributor

Bumps gixy-ng from 0.2.46 to 0.2.47.

Release notes

Sourced from gixy-ng's releases.

v0.2.47

Added

  • nginx_cves: New entry CVE-2026-9256 — heap memory buffer overflow in ngx_http_rewrite_module triggered by a configuration with overlapping captures, potentially resulting in arbitrary code execution in a worker process. Affects nginx OSS 0.1.17..1.31.0. Mitigation: upgrade to 1.31.1 (mainline) or 1.30.2 (stable). The check fires purely on --nginx-version= match — --nginx-version=1.31.0 (previously considered patched) now reports this CVE. Advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9256, nginx CHANGES-1.30: https://nginx.org/en/CHANGES-1.30. Credit: Mufeed VH of Winfunc Research.

Full changelog: https://github.com/dvershinin/gixy/blob/v0.2.47/CHANGELOG.md

Changelog

Sourced from gixy-ng's changelog.

[0.2.47] - 2026-05-23

Added

  • nginx_cves: New entry CVE-2026-9256 — heap memory buffer overflow in ngx_http_rewrite_module triggered by a configuration with overlapping captures, potentially resulting in arbitrary code execution in a worker process. Affects nginx OSS 0.1.17..1.31.0. Mitigation: upgrade to 1.31.1 (mainline) or 1.30.2 (stable). The check fires purely on --nginx-version= match — --nginx-version=1.31.0 (previously considered patched) now reports this CVE. Advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9256, nginx CHANGES-1.30: https://nginx.org/en/CHANGES-1.30. Credit: Mufeed VH of Winfunc Research.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [gixy-ng](https://github.com/dvershinin/gixy) from 0.2.46 to 0.2.47.
- [Release notes](https://github.com/dvershinin/gixy/releases)
- [Changelog](https://github.com/dvershinin/gixy/blob/master/CHANGELOG.md)
- [Commits](dvershinin/gixy@v0.2.46...v0.2.47)

---
updated-dependencies:
- dependency-name: gixy-ng
  dependency-version: 0.2.47
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 25, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 25, 2026

Copy link
Copy Markdown
Contributor Author

Looks like gixy-ng is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this May 25, 2026
@dependabot dependabot Bot deleted the dependabot/pip/main/gixy-ng-0.2.47 branch May 25, 2026 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants