CVE-2026-33658
- EPSS 0.43%
- Veröffentlicht 26.03.2026 21:03:25
- Zuletzt bearbeitet 30.04.2026 19:02:21
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thou...
CVE-2026-33202
- EPSS 0.65%
- Veröffentlicht 23.03.2026 23:34:52
- Zuletzt bearbeitet 24.03.2026 17:55:12
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metachara...
CVE-2026-33195
- EPSS 0.57%
- Veröffentlicht 23.03.2026 23:31:41
- Zuletzt bearbeitet 15.07.2026 02:20:09
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage...
CVE-2026-33176
- EPSS 0.61%
- Veröffentlicht 23.03.2026 23:29:27
- Zuletzt bearbeitet 24.03.2026 17:55:27
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`...
CVE-2026-33174
- EPSS 0.61%
- Veröffentlicht 23.03.2026 23:24:55
- Zuletzt bearbeitet 24.03.2026 17:55:58
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte ...
CVE-2026-33173
- EPSS 0.39%
- Veröffentlicht 23.03.2026 23:21:29
- Zuletzt bearbeitet 24.03.2026 17:56:09
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal fla...
CVE-2026-33167
- EPSS 0.25%
- Veröffentlicht 23.03.2026 23:17:12
- Zuletzt bearbeitet 12.08.2026 16:45:36
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject a...
CVE-2026-33170
- EPSS 0.33%
- Veröffentlicht 23.03.2026 23:09:48
- Zuletzt bearbeitet 24.03.2026 18:00:00
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a...
CVE-2026-33169
- EPSS 0.5%
- Veröffentlicht 23.03.2026 23:07:07
- Zuletzt bearbeitet 24.03.2026 18:01:08
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters. Prior to versions 8.1.2....
CVE-2024-47889
- EPSS 0.94%
- Veröffentlicht 16.10.2024 21:15:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully cr...