pagy
Agnostic pagination in plain ruby
Activity
- Latest release
- 3w ago
- Total releases
- 265
- Cadence
- ~3 days
- Last 12 months
- 47
Reach
- Downloads
- 42.5M
- Stars
- 5.0k
Details
- License
- MIT
- First release
- Feb 12, 2018
| Version | Released | |
|---|---|---|
43.6.2
patch
| ||
43.6.1
patch
| ||
43.6.0
minor
| ||
43.5.6
patch
| ||
43.5.5
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.5.4
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.5.3
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.5.2
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.5.1
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.5.0
minor
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.4.4
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.4.3
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.4.2
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.4.1
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.4.0
minor
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.3.3
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.3.2
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.3.1
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.3.0
minor
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.10
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.9
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.8
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.7
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.6
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.5
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.4
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.3
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.2
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.1
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.2.0
minor
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.8
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.7
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.6
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.5
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.4
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.3
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.2
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.1
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.1.0
minor
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.7
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.6
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.5
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.4
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.3
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.2
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.1
patch
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.0
major
1 CVE
CVE-2026-54659
GHSA-2xmw-f8j8-wfxc
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Medium
Network
Low
None
None
Summary
DetailsThe setter stored the value as-is, and the loader joined it into a path and read it:
Because the locale was used verbatim, a value such as an absolute path or
a Fixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:
Any non-matching value (including PoCIn an application that sets
ImpactInformation disclosure (CWE-22 / CWE-200): a file-existence / readability
oracle for Only applications that pass unsanitized end-user input into
Patched: pagy 43.5.6.
Workaround (if you cannot upgrade): validate the locale before
assigning it, e.g.
Affected versions
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
+ 31 more Show less
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5
Fixed in
43.5.6
References Updated Jul 28, 2026 · Source: OSV.dev | ||
43.0.0.rc4
pre
| ||
43.0.0.rc3
pre
| ||
9.4.0
minor
|