Ruby on Rails Discussions


Topic Replies Views Activity
About the Security Announcements category 0 4673 October 16, 2020
[CVE-2026-66066] Attack details, and tools to perform a forensic investigation 1 3158 August 1, 2026
[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing 0 10124 July 29, 2026
[GHSA-cj75-f6xr-r4g7] Possible XSS vulnerability with certain configurations of rails-html-sanitizer 0 275 July 16, 2026
[CVE-2026-33167] Possible XSS vulnerability in Action Pack debug exceptions 0 785 March 23, 2026
[CVE-2026-33168] Possible XSS vulnerability in Action View tag helpers 0 432 March 23, 2026
[CVE-2026-33169] Possible ReDoS vulnerability in number_to_delimited in Active Support 0 366 March 23, 2026
[CVE-2026-33170] Possible XSS vulnerability in SafeBuffer#% in Active Support 0 361 March 23, 2026
[CVE-2026-33173] Insufficient filtering of metadata in Active Storage direct uploads 0 319 March 23, 2026
[CVE-2026-33174] Possible DoS vulnerability in Active Storage proxy mode via Range requests 0 300 March 23, 2026
[CVE-2026-33176] Possible DoS vulnerability in Active Support number helpers 0 347 March 23, 2026
[CVE-2026-33658] Possible DoS vulnerability in Active Storage proxy mode via multi-range requests 0 396 March 23, 2026
This was a previous vulnerability re-published by mistake. Please ignore CVE-2026-33178 0 90 March 23, 2026
[CVE-2026-33195] Possible path traversal in Active Storage DiskService 0 345 March 23, 2026
[CVE-2026-33202] Possible glob injection in Active Storage DiskService 0 303 March 23, 2026
[CVE-2025-24293] Active Storage allowed transformation methods potentially unsafe 0 1964 August 13, 2025
[CVE-2025-55193] ANSI escape injection in Active Record logging 0 1103 August 13, 2025
[CVE-2024-47889] Possible ReDoS vulnerability in block_format in Action Mailer 0 925 October 15, 2024
[CVE-2024-54133] Possible Content Security Policy bypass in Action Dispatch 0 1433 December 10, 2024
Rails-html-sanitizer v1.6.1 addresses multiple CVEs 0 601 December 2, 2024
[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text 0 599 October 15, 2024
[CVE-2024-41128] Possible ReDoS vulnerability in query parameter filtering in Action Dispatch 0 831 October 15, 2024
[CVE-2024-47887] Possible ReDoS vulnerability in HTTP Token authentication in Action Controller 0 920 October 15, 2024
[CVE-2024-32464] ActionText ContentAttachment's can Contain Unsanitized HTML 0 2344 June 4, 2024
[CVE-2024-28103] Permissions-Policy is Only Served on HTML Content-Type 0 1926 June 4, 2024
XSS Vulnerabilities in Trix Editor 0 1860 May 17, 2024
Possible XSS Vulnerability in Action Controller 2 8165 February 27, 2024
Possible Denial of Service Vulnerability in Rack Header Parsing 0 4718 February 21, 2024
Possible ReDoS vulnerability in Accept header parsing in Action Dispatch 0 3972 February 21, 2024
Denial of Service Vulnerability in Rack Content-Type Parsing 0 5086 February 21, 2024

Read the original on discuss.rubyonrails.org ↗