CVE IDs : CVE-2023-28755 CVE-2023-28756
Two regular expression Denial of Service (ReDoS) issues were discovered in Ruby: the first in the URI component, and the second in the Time module. Each of these issues could have resulted in a dramatic increase in execution time given malicious input.
2.5.5-3+deb10u5