Update mail to 2.9.1 for GHSA-mvxr-6m87-mv2q (#248)

The advisory (email address spoofing via malformed RFC 2047
encoded-words, CVE-2026-63435) landed in ruby-advisory-db on
2026-08-18, turning the gem audit red since the audit pulls a live
advisory DB. 2.9.1 is the patch release for exactly this CVE.
This commit is contained in:
Jeremy Daer
2026-08-18 16:47:08 -07:00
committed by GitHub
parent f1aec61336
commit e33b7e50c9
+1 -1
View File
@@ -204,7 +204,7 @@ GEM
loofah (2.25.2)
crass (~> 1.0.2)
nokogiri (>= 1.12.0)
mail (2.9.0)
mail (2.9.1)
logger
mini_mime (>= 0.1.1)
net-imap