Ruby 4.0.3 has been released. It updates ERB to 6.0.1.1 for CVE-2026-41316.
If your application calls Marshal.load on untrusted data AND has both erb and activesupport loaded, please update your ERB version. You may update Ruby to 4.0.3 to do so.
www.ruby-lang.org/en/news/2026...