rails
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting rails.
- CVE-2026-73648rails-html-sanitizer: Possible XSS vulnerability with certain configurations
- CVE-2026-66066Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
- CVE-2026-33658Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests6.5
- CVE-2026-33202Rails Active Storage has possible glob injection in its DiskService9.1
- CVE-2026-33195Rails Active Storage has possible Path Traversal in DiskService9.8
- CVE-2026-33176Rails Active Support has a possible DoS vulnerability in its number helpers7.5
- CVE-2026-33174Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests7.5
- CVE-2026-33173Rails Active Storage has possible content type bypass via metadata in direct uploads5.3
- CVE-2026-33170Rails Active Support has a possible XSS vulnerability in SafeBuffer#%6.1
- CVE-2026-33169Rails Active Support has a possible ReDoS vulnerability in number_to_delimited5.3
- CVE-2026-33168Rails has a possible XSS vulnerability in its Action View tag helpers6.5
- CVE-2026-33167Rails has a possible XSS vulnerability in its Action Pack debug exceptions6.1
- CVE-2025-24293# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. Th...8.1
- CVE-2025-55193Active Record logging vulnerable to ANSI escape injection
- CVE-2023-38037ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's ...5.5