GHSA-r275-j57c-7mf2
GitHub Security Advisory
Race condition in Endorsements
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
### Impact
A race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement.
To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel.
### Workarounds
Disable the Endorsement feature in the components.
Affected Packages
RubyGems
decidim
Affected versions:
0.10.0
(fixed in 0.26.9)
RubyGems
decidim
Affected versions:
0.27.0
(fixed in 0.27.5)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: July 13, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.