This advisory claims the affected css_parser versions as < 3.0.0: GHSA-9pmc-p236-855h https://github.com/advisories/GHSA-9pmc-p236-855h.
However, this advisory claims the affected css_parser version is only 2.2.0: GHSA-9pmc-p236-855h https://github.com/premailer/css_parser/security/advisories/GHSA-9pmc-p236-855h.
Which of these is correct?
If the affected versions are < 3.0.0, then ruby-advisory-db will need updating too: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/css_parser/CVE-2026-53727.yml
This advisory claims the affected css_parser versions as
< 3.0.0: GHSA-9pmc-p236-855hhttps://github.com/advisories/GHSA-9pmc-p236-855h.However, this advisory claims the affected css_parser version is only
2.2.0: GHSA-9pmc-p236-855hhttps://github.com/premailer/css_parser/security/advisories/GHSA-9pmc-p236-855h.Which of these is correct?
If the affected versions are
< 3.0.0, then ruby-advisory-db will need updating too: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/css_parser/CVE-2026-53727.yml