|
About the Security Announcements category
|
|
0
|
4672
|
October 16, 2020
|
|
[CVE-2026-66066] Attack details, and tools to perform a forensic investigation
|
|
1
|
3034
|
August 1, 2026
|
|
[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing
|
|
0
|
9798
|
July 29, 2026
|
|
[GHSA-cj75-f6xr-r4g7] Possible XSS vulnerability with certain configurations of rails-html-sanitizer
|
|
0
|
263
|
July 16, 2026
|
|
[CVE-2026-33167] Possible XSS vulnerability in Action Pack debug exceptions
|
|
0
|
779
|
March 23, 2026
|
|
[CVE-2026-33168] Possible XSS vulnerability in Action View tag helpers
|
|
0
|
429
|
March 23, 2026
|
|
[CVE-2026-33169] Possible ReDoS vulnerability in number_to_delimited in Active Support
|
|
0
|
365
|
March 23, 2026
|
|
[CVE-2026-33170] Possible XSS vulnerability in SafeBuffer#% in Active Support
|
|
0
|
359
|
March 23, 2026
|
|
[CVE-2026-33173] Insufficient filtering of metadata in Active Storage direct uploads
|
|
0
|
317
|
March 23, 2026
|
|
[CVE-2026-33174] Possible DoS vulnerability in Active Storage proxy mode via Range requests
|
|
0
|
295
|
March 23, 2026
|
|
[CVE-2026-33176] Possible DoS vulnerability in Active Support number helpers
|
|
0
|
342
|
March 23, 2026
|
|
[CVE-2026-33658] Possible DoS vulnerability in Active Storage proxy mode via multi-range requests
|
|
0
|
395
|
March 23, 2026
|
|
This was a previous vulnerability re-published by mistake. Please ignore CVE-2026-33178
|
|
0
|
90
|
March 23, 2026
|
|
[CVE-2026-33195] Possible path traversal in Active Storage DiskService
|
|
0
|
343
|
March 23, 2026
|
|
[CVE-2026-33202] Possible glob injection in Active Storage DiskService
|
|
0
|
302
|
March 23, 2026
|
|
[CVE-2025-24293] Active Storage allowed transformation methods potentially unsafe
|
|
0
|
1957
|
August 13, 2025
|
|
[CVE-2025-55193] ANSI escape injection in Active Record logging
|
|
0
|
1100
|
August 13, 2025
|
|
[CVE-2024-47889] Possible ReDoS vulnerability in block_format in Action Mailer
|
|
0
|
924
|
October 15, 2024
|
|
[CVE-2024-54133] Possible Content Security Policy bypass in Action Dispatch
|
|
0
|
1427
|
December 10, 2024
|
|
Rails-html-sanitizer v1.6.1 addresses multiple CVEs
|
|
0
|
600
|
December 2, 2024
|
|
[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
|
|
0
|
597
|
October 15, 2024
|
|
[CVE-2024-41128] Possible ReDoS vulnerability in query parameter filtering in Action Dispatch
|
|
0
|
830
|
October 15, 2024
|
|
[CVE-2024-47887] Possible ReDoS vulnerability in HTTP Token authentication in Action Controller
|
|
0
|
920
|
October 15, 2024
|
|
[CVE-2024-32464] ActionText ContentAttachment's can Contain Unsanitized HTML
|
|
0
|
2343
|
June 4, 2024
|
|
[CVE-2024-28103] Permissions-Policy is Only Served on HTML Content-Type
|
|
0
|
1926
|
June 4, 2024
|
|
XSS Vulnerabilities in Trix Editor
|
|
0
|
1858
|
May 17, 2024
|
|
Possible XSS Vulnerability in Action Controller
|
|
2
|
8165
|
February 27, 2024
|
|
Possible Denial of Service Vulnerability in Rack Header Parsing
|
|
0
|
4715
|
February 21, 2024
|
|
Possible ReDoS vulnerability in Accept header parsing in Action Dispatch
|
|
0
|
3972
|
February 21, 2024
|
|
Denial of Service Vulnerability in Rack Content-Type Parsing
|
|
0
|
5086
|
February 21, 2024
|