Issue #22005 has been updated by hsbt (Hiroshi SHIBATA). Status changed from Open to Closed Assignee set to hsbt (Hiroshi SHIBATA) I published https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r yesterday. After that, https://www.cve.org/CVERecord?id=CVE-2026-27820 is available now. It seems that CVEs issued from GitHub are not published on cve.org unless the GHSA is also published. From now on, I will publish the GHSA at the same time. Thank you for pointing this. ---------------------------------------- Misc #22005: Missing information about CVE on cve.org https://bugs.ruby-lang.org/issues/22005#change-117045 * Author: vo.x (Vit Ondruch) * Status: Closed * Assignee: hsbt (Hiroshi SHIBATA) ---------------------------------------- The CVE-2026-27820 was fixed and disclosed more than one month ago: https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-2... However, there is still no public information on https://www.cve.org/CVERecord?id=CVE-2026-27820 . Could this be fixed please? BTW the same situation was for CVE-2025-61594, where the information was not there for months. This points to a gap in a security release process. Could the process be improved so the information is disclosed in timely manner? -- https://bugs.ruby-lang.org/