vciy

CVEs we hold for Rails

Records whose assigning authority named Rails as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-73648rails-html-sanitizer: Possible XSS vulnerability with certain configurationsrails-html-sanitizer
CVE-2026-66066Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingrails
CVE-2026-33658Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requestsrails activestorage
CVE-2026-33202Rails Active Storage has possible glob injection in its DiskServicerails activestorage
CVE-2026-33195Rails Active Storage has possible Path Traversal in DiskServicerails activestorage
CVE-2026-33176Rails Active Support has a possible DoS vulnerability in its number helpersrails activesupport
CVE-2026-33174Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requestsrails activestorage
CVE-2026-33173Rails Active Storage has possible content type bypass via metadata in direct uploadsrails activestorage
CVE-2026-33170Rails Active Support has a possible XSS vulnerability in SafeBuffer#%rails activesupport
CVE-2026-33169Rails Active Support has a possible ReDoS vulnerability in number_to_delimitedrails activesupport
CVE-2026-33168Rails has a possible XSS vulnerability in its Action View tag helpersrails actionview
CVE-2026-33167Rails has a possible XSS vulnerability in its Action Pack debug exceptionsrails actionpack
CVE-2025-55193Active Record logging vulnerable to ANSI escape injectionrails
CVE-2025-24293no title heldRails activestorage
CVE-2024-54133Possible Content Security Policy bypass in Action Dispatchrails
CVE-2024-53989Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53988Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53987Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53986Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53985Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-47889Action Mailer has possible ReDoS vulnerability in block_formatrails
CVE-2024-47888Action Text has possible ReDoS vulnerability in plain_text_for_blockquote_noderails
CVE-2024-47887Action Controller has possible ReDoS vulnerability in HTTP Token authenticationrails
CVE-2024-41128Action Dispatch has possible ReDoS vulnerability in query parameter filteringrails
CVE-2024-39308RailsAdmin Cross-site Scripting vulnerability in the list viewrailsadminteam rails_admin
CVE-2024-32464ActionText ContentAttachment can Contain Unsanitized HTMLrails
CVE-2024-28103Action Pack is missing security headers on non-HTML responsesrails
CVE-2024-26144Possible Sensitive Session Information Leak in Active Storagerails
CVE-2024-26143Rails Possible XSS Vulnerability in Action Controllerrails
CVE-2024-26142Rails possible ReDoS vulnerability in Accept header parsing in Action Dispatchrails
CVE-2023-38037no title heldRails ActiveSupport
CVE-2023-28362no title heldRails Action Pack
CVE-2023-28120no title heldRails ActiveSupport
CVE-2023-27539no title heldRails Rack
CVE-2023-27531no title heldRails Kredis JSON
CVE-2023-23913no title heldrails-ujs
CVE-2022-23633Exposure of sensitive information in Action Packrails
CVE-2022-23520rails-html-sanitizer contains an incomplete fix for an XSS vulnerabilityrails-html-sanitizer
CVE-2022-23519Possible XSS vulnerability with certain configurations of rails-html-sanitizerrails-html-sanitizer
CVE-2022-23518Improper neutralization of data URIs allows XSS in rails-html-sanitizerrails-html-sanitizer
CVE-2022-23517Inefficient Regular Expression Complexity in rails-html-sanitizerrails-html-sanitizer
CVE-2020-5267Possible XSS vulnerability in ActionViewrails actionview
CVE-2020-15169XSS in Action Viewrails actionview
CVE-2019-5420no title heldRails https://github.com/rails/rails
CVE-2019-5419no title heldRails https://github.com/rails/rails
CVE-2019-5418no title heldRails https://github.com/rails/rails
CVE-2018-3741no title heldrails-html-sanitizer
CVE-2014-125033rails-cv-app uploaded_files_controller.rb path traversaln/a rails-cv-app
CVE-2011-1497no title heldn/a rails
CVE-2010-3299no title heldrails

50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.