Skip to content

Bump dalli from 5.1.0 to 5.1.1 - #1921

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/dalli-5.1.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/dalli-5.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps dalli from 5.1.0 to 5.1.1.

Release notes

Sourced from dalli's releases.

v5.1.1

Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.

Security:

  • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
    • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
    • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
    • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
    • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
    • Thanks to oss-security-shop for the report

Performance:

  • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
    • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
    • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
    • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
    • Allocations per get hit drop from 23 to 16
    • Thanks to Julian Richard Contreras for this contribution
  • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
    • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
    • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
    • Pipelined replies are parsed in one pass over the returned flags
    • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
    • Thanks to Julian Richard Contreras for this contribution

Development:

  • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
    • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
    • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
Changelog

Sourced from dalli's changelog.

5.1.1

Security:

  • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
    • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
    • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
    • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
    • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
    • Thanks to oss-security-shop for the report

Performance:

  • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
    • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
    • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
    • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
    • Allocations per get hit drop from 23 to 16
    • Thanks to Julian Richard Contreras for this contribution
  • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
    • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
    • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
    • Pipelined replies are parsed in one pass over the returned flags
    • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
    • Thanks to Julian Richard Contreras for this contribution

Development:

  • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
    • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
    • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
Commits
  • 7bd7daf Merge commit from fork
  • e3b73f6 Prepare 5.1.1 release
  • 5d6b470 Reject non-integer numeric flags in meta protocol commands
  • 473932d Merge pull request #1163 from petergoldstein/docs/changelog-1160-1161-1162
  • 4c20d0c Update CHANGELOG for #1160, #1161 and #1162
  • a2dac30 Merge pull request #1161 from radixdev/perf/faster-multi-server-get-multi
  • dd81192 Add PR number to changelog entry
  • 7b974e5 Speed up multi-server get_multi
  • 3c6e9c6 Merge pull request #1160 from radixdev/perf/faster-single-get
  • 758d1b9 Treat false options like nil on the get fast path
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dalli](https://github.com/petergoldstein/dalli) from 5.1.0 to 5.1.1.
- [Release notes](https://github.com/petergoldstein/dalli/releases)
- [Changelog](https://github.com/petergoldstein/dalli/blob/main/CHANGELOG.md)
- [Commits](petergoldstein/dalli@v5.1.0...v5.1.1)

---
updated-dependencies:
- dependency-name: dalli
  dependency-version: 5.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies ruby Pull requests that update ruby code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants