Skip to main content

Vendor/product archive

rubyonrails / rails CVEs

Beta · best-effort

121 CVEs tagged to rubyonrails / rails3 Critical, 37 High, 78 Medium, 3 Low, 0 Unrated.

CVE-2026-33658

Published Mar 26, 2026

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-33202

Published Mar 24, 2026

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed`…

CVSS 6.6 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-33195

Published Mar 24, 2026

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does no…

CVSS 8.0 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-33176

Published Mar 24, 2026

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support numbe…

CVSS 6.6 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-33174

Published Mar 24, 2026

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's pro…

CVSS 6.6 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-33173

Published Mar 24, 2026

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary met…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-33170

Published Mar 24, 2026

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-33169

Published Mar 24, 2026

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expressio…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2024-32464

Published Jun 4, 2024

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain un…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28103

Published Jun 4, 2024

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML relat…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26144

Published Feb 27, 2024

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26143

Published Feb 27, 2024

Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like tr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26142

Published Feb 27, 2024

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22792

Published Feb 9, 2023

A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HO…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3704

Published Oct 26, 2022

A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_tab…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-44528

Published Jan 10, 2022

A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1497

Published Oct 19, 2021

A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22942

Published Oct 18, 2021

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22904

Published Jun 11, 2021

The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22903

Published Jun 11, 2021

The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can c…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 121 CVEsPage 1 of 5