|
[CVE-2026-33167] Possible XSS vulnerability in Action Pack debug exceptions
|
|
0
|
507
|
March 23, 2026
|
|
[CVE-2026-33168] Possible XSS vulnerability in Action View tag helpers
|
|
0
|
320
|
March 23, 2026
|
|
[CVE-2026-33169] Possible ReDoS vulnerability in number_to_delimited in Active Support
|
|
0
|
276
|
March 23, 2026
|
|
[CVE-2026-33170] Possible XSS vulnerability in SafeBuffer#% in Active Support
|
|
0
|
237
|
March 23, 2026
|
|
[CVE-2026-33173] Insufficient filtering of metadata in Active Storage direct uploads
|
|
0
|
224
|
March 23, 2026
|
|
[CVE-2026-33174] Possible DoS vulnerability in Active Storage proxy mode via Range requests
|
|
0
|
221
|
March 23, 2026
|
|
[CVE-2026-33176] Possible DoS vulnerability in Active Support number helpers
|
|
0
|
250
|
March 23, 2026
|
|
[CVE-2026-33658] Possible DoS vulnerability in Active Storage proxy mode via multi-range requests
|
|
0
|
313
|
March 23, 2026
|
|
This was a previous vulnerability re-published by mistake. Please ignore CVE-2026-33178
|
|
0
|
63
|
March 23, 2026
|
|
[CVE-2026-33195] Possible path traversal in Active Storage DiskService
|
|
0
|
228
|
March 23, 2026
|
|
[CVE-2026-33202] Possible glob injection in Active Storage DiskService
|
|
0
|
237
|
March 23, 2026
|
|
Clarification request: are security reports for EOL releases assessed?
|
|
3
|
158
|
October 18, 2025
|
|
[CVE-2025-24293] Active Storage allowed transformation methods potentially unsafe
|
|
0
|
1792
|
August 13, 2025
|
|
[CVE-2025-55193] ANSI escape injection in Active Record logging
|
|
0
|
1049
|
August 13, 2025
|
|
Find_by using params.expect - vulnerable to SQL injection?
|
|
8
|
320
|
August 7, 2025
|
|
Security says CSRF token should be a nonce
|
|
1
|
214
|
May 15, 2025
|
|
Is `accept_nested_attributes_for` considered safe when used with Delegated Types?
|
|
5
|
357
|
March 10, 2025
|
|
Add salt in user password to make more scure?
|
|
3
|
237
|
February 26, 2025
|
|
[CVE-2024-47889] Possible ReDoS vulnerability in block_format in Action Mailer
|
|
0
|
904
|
October 15, 2024
|
|
[CVE-2024-54133] Possible Content Security Policy bypass in Action Dispatch
|
|
0
|
1365
|
December 10, 2024
|
|
How to implement key rotation for deterministic encryption?
|
|
0
|
140
|
December 5, 2024
|
|
[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
|
|
0
|
585
|
October 15, 2024
|
|
[CVE-2024-41128] Possible ReDoS vulnerability in query parameter filtering in Action Dispatch
|
|
0
|
811
|
October 15, 2024
|
|
[CVE-2024-47887] Possible ReDoS vulnerability in HTTP Token authentication in Action Controller
|
|
0
|
905
|
October 15, 2024
|
|
How to implement secret rotation?
|
|
4
|
2046
|
November 20, 2023
|
|
[CVE-2023-38037] Possible File Disclosure of Locally Encrypted Files
|
|
0
|
6208
|
August 22, 2023
|
|
[CVE-2023-28362] Possible XSS via User Supplied Values to redirect_to
|
|
0
|
12305
|
June 26, 2023
|
|
[CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID
|
|
0
|
6097
|
January 17, 2023
|
|
[CVE-2022-44572] Possible Denial of Service Vulnerability in Rack's RFC2183 boundary parsing
|
|
0
|
4558
|
January 17, 2023
|
|
[CVE-2022-44571] Possible Denial of Service Vulnerability in Rack Content-Disposition parsing
|
|
0
|
6870
|
January 17, 2023
|