CVEs we hold for Rails
Records whose assigning authority named Rails as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73648rails-html-sanitizer: Possible XSS vulnerability with certain configurationsrails-html-sanitizer
CVE-2026-66066Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingrails
CVE-2026-33658Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requestsrails activestorage
CVE-2026-33202Rails Active Storage has possible glob injection in its DiskServicerails activestorage
CVE-2026-33176Rails Active Support has a possible DoS vulnerability in its number helpersrails activesupport
CVE-2026-33174Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requestsrails activestorage
CVE-2026-33173Rails Active Storage has possible content type bypass via metadata in direct uploadsrails activestorage
CVE-2026-33170Rails Active Support has a possible XSS vulnerability in SafeBuffer#%rails activesupport
CVE-2026-33169Rails Active Support has a possible ReDoS vulnerability in number_to_delimitedrails activesupport
CVE-2026-33167Rails has a possible XSS vulnerability in its Action Pack debug exceptionsrails actionpack
CVE-2024-53989Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53988Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53987Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53986Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-53985Possible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0rails-html-sanitizer
CVE-2024-39308RailsAdmin Cross-site Scripting vulnerability in the list viewrailsadminteam rails_admin
CVE-2022-23520rails-html-sanitizer contains an incomplete fix for an XSS vulnerabilityrails-html-sanitizer
CVE-2022-23519Possible XSS vulnerability with certain configurations of rails-html-sanitizerrails-html-sanitizer
CVE-2022-23518Improper neutralization of data URIs allows XSS in rails-html-sanitizerrails-html-sanitizer
50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.