activestorage
Ruby on Rails
Activity
- Latest release
- 1mo ago
- Total releases
- 184
- Cadence
- ~daily
- Last 12 months
- 16
Reach
- Stars
- 58.7k
Details
- License
- MIT
- First release
- Jul 06, 2017
| Version | Released | |
|---|---|---|
8.0.5.1
patch
| ||
7.2.3.2
patch
| ||
8.1.3.1
patch
| ||
8.1.3
patch
1 CVE
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.0.5
patch
1 CVE
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.1.2.1
patch
1 CVE
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.0.4.1
patch
1 CVE
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.2.3.1
patch
1 CVE
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.1.2
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.1.1
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.0.4
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.2.3
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.1.6
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.0.10
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
8.1.0
minor
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.1.0.rc1
pre
5 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.0.3
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.1.0.beta1
pre
5 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.1.0.beta1
pre
Dependencies (5)
Changelog
Compare changes
|
|
8.0.2.1
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.2.2.2
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.1.5.2
patch
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
8.0.2
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
8.0.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
8.0.0.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.0.8.7
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
7.0.8.7
patch
Dependencies (6)
Changelog
Compare changes
|
|
7.2.2.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.1.5.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
8.0.0
major
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.2.2
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.1.5
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
8.0.0.rc2
pre
5 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.1.4.2
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
6.1.7.10
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
6.1.7.10
patch
Dependencies (6)
Changelog
Compare changes
|
|
7.2.1.2
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.0.8.6
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
7.0.8.6
patch
Dependencies (6)
Changelog
Compare changes
|
|
8.0.0.rc1
pre
5 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.2.1.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
6.1.7.9
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
6.1.7.9
patch
Dependencies (6)
Changelog
Compare changes
|
|
7.1.4.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.0.8.5
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
7.0.8.5
patch
Dependencies (6)
Changelog
Compare changes
|
|
8.0.0.beta1
pre
5 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
8.0.0.beta1
pre
Dependencies (5)
Changelog
Compare changes
|
|
7.1.4
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.2.1
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.2.0
minor
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
7.2.0.rc1
pre
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
7.2.0.beta3
pre
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.2.0.beta3
pre
Dependencies (5)
Changelog
Compare changes
|
|
7.2.0.beta2
pre
6 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.2.0.beta2
pre
Dependencies (5)
Changelog
Compare changes
|
|
7.0.8.4
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
7.0.8.4
patch
Dependencies (6)
Changelog
Compare changes
|
|
7.1.3.4
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev | ||
6.1.7.8
patch
7 CVEs
CVE-2026-66066
GHSA-xr9x-r78c-5hrm
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
Network
Low
None
None
ImpactIn its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds Detailslibvips reads and writes file formats through "loaders" and "savers" (or more generally "operations"), many of which are backed by third-party libraries. It marks some of these operations as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload a crafted file and cause a variant to be generated from it may be able to invoke one. We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause disclosure of the contents of arbitrary files accessible on the filesystem of the targeted application. One specific attack chain has been reported to us (see "Disclosure" below), but we do not assume it is the only one that exists. Affected applicationsAn application is affected if it meets all of these requirements:
Generating variants is not a separate requirement. Mitigation
Earlier versions of libvips ( Expire and change secretsUpgrading closes the vulnerability but does not undo an exfiltrated secret if that already occurred. An affected application should treat every secret readable by the application process as potentially exposed and change it, including:
Changing Rotation should only be used as an intermediate step if necessary. Do not retain an exposed secret as a fallback. WorkaroundsIf libvips If libvips Applications also running ruby-vips ReleasesThe fixed releases are available at the normal locations. Versions affected
DisclosureTechnical details of the attack chain are intentionally omitted from this advisory. They would add nothing to an administrator's decision to upgrade, while making it substantially easier to attack applications that have not yet done so. Details will be disclosed no later than 2026-08-28, via the Rails Security Announcements forum. CreditThis issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho from Ethiack, and RyotaK from GMO Flatt Security Inc.. References
Affected versions
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
+ 169 more Show less
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
7.2.3.1
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
8.0.4.1
8.0.5
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.1.2.1
8.1.3
Fixed in
7.2.3.2
8.0.5.1
8.1.3.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33658
GHSA-p9fm-f462-ggrg
Mar 25, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
Network
Low
Low
None
ImpactActive Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher thwin_htet. Affected versions
8.1.0
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.1
8.0.2
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
+ 159 more Show less
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33202
GHSA-73f9-jhhh-hr5m
Mar 23, 2026
Rails Active Storage has possible glob injection in its DiskService
Medium
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33195
GHSA-9xrj-h377-fr87
Mar 23, 2026
Rails Active Storage has possible Path Traversal in DiskService
High
Network
Low
None
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone researcher ksw9722. Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33174
GHSA-r46p-8f7g-vvvg
Mar 23, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Medium
Network
Low
None
None
ImpactWhen serving files through Active Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis issue was responsibly reported by Hackerone user pirikara Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33173
GHSA-qcfx-2mfw-w4cg
Mar 23, 2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Medium
Network
Low
None
ImpactActive Storage's ReleasesThe fixed releases are available at the normal locations. CreditThis was responsible reported by Hackerone researcher pwnie Affected versions
8.1.0
8.1.0.beta1
8.1.0.rc1
8.1.1
8.1.2
8.0.0
8.0.0.1
8.0.0.beta1
8.0.0.rc1
8.0.0.rc2
8.0.1
8.0.2
+ 164 more Show less
8.0.2.1
8.0.3
8.0.4
0.1
5.2.0
5.2.0.beta1
5.2.0.beta2
5.2.0.rc1
5.2.0.rc2
5.2.1
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
7.1.5.2
7.1.6
7.2.0
7.2.0.beta1
7.2.0.beta2
7.2.0.beta3
7.2.0.rc1
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
7.2.2.2
7.2.3
Fixed in
7.2.3.1
8.0.4.1
8.1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24293
GHSA-r4mg-4433-c7g3
Aug 14, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
Network
Low
None
None
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. This has been assigned the CVE identifier CVE-2025-24293. Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.1.5.2, 7.2.2.2, 8.0.2.1 ImpactThis vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this:
Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. ReleasesThe fixed releases are available at the normal locations. WorkaroundsConsuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong ImageMagick security policy deployed. CreditsThank you lio346 from Unit 515 of OPSWAT for reporting this! Affected versions
8.0.0
8.0.0.1
8.0.1
8.0.2
7.2.0
7.2.1
7.2.1.1
7.2.1.2
7.2.2
7.2.2.1
5.2.0
5.2.1
+ 140 more Show less
5.2.1.1
5.2.1.rc1
5.2.2
5.2.2.1
5.2.2.rc1
5.2.3
5.2.3.rc1
5.2.4
5.2.4.1
5.2.4.2
5.2.4.3
5.2.4.4
5.2.4.5
5.2.4.6
5.2.4.rc1
5.2.5
5.2.6
5.2.6.1
5.2.6.2
5.2.6.3
5.2.7
5.2.7.1
5.2.8
5.2.8.1
6.0.0
6.0.0.beta1
6.0.0.beta2
6.0.0.beta3
6.0.0.rc1
6.0.0.rc2
6.0.1
6.0.1.rc1
6.0.2
6.0.2.1
6.0.2.2
6.0.2.rc1
6.0.2.rc2
6.0.3
6.0.3.1
6.0.3.2
6.0.3.3
6.0.3.4
6.0.3.5
6.0.3.6
6.0.3.7
6.0.3.rc1
6.0.4
6.0.4.1
6.0.4.2
6.0.4.3
6.0.4.4
6.0.4.5
6.0.4.6
6.0.4.7
6.0.4.8
6.0.5
6.0.5.1
6.0.6
6.0.6.1
6.1.0
6.1.0.rc1
6.1.0.rc2
6.1.1
6.1.2
6.1.2.1
6.1.3
6.1.3.1
6.1.3.2
6.1.4
6.1.4.1
6.1.4.2
6.1.4.3
6.1.4.4
6.1.4.5
6.1.4.6
6.1.4.7
6.1.5
6.1.5.1
6.1.6
6.1.6.1
6.1.7
6.1.7.1
6.1.7.10
6.1.7.2
6.1.7.3
6.1.7.4
6.1.7.5
6.1.7.6
6.1.7.7
6.1.7.8
6.1.7.9
7.0.0
7.0.0.alpha1
7.0.0.alpha2
7.0.0.rc1
7.0.0.rc2
7.0.0.rc3
7.0.1
7.0.10
7.0.2
7.0.2.1
7.0.2.2
7.0.2.3
7.0.2.4
7.0.3
7.0.3.1
7.0.4
7.0.4.1
7.0.4.2
7.0.4.3
7.0.5
7.0.5.1
7.0.6
7.0.7
7.0.7.1
7.0.7.2
7.0.8
7.0.8.1
7.0.8.2
7.0.8.3
7.0.8.4
7.0.8.5
7.0.8.6
7.0.8.7
7.1.0
7.1.0.beta1
7.1.0.rc1
7.1.0.rc2
7.1.1
7.1.2
7.1.3
7.1.3.1
7.1.3.2
7.1.3.3
7.1.3.4
7.1.4
7.1.4.1
7.1.4.2
7.1.5
7.1.5.1
Fixed in
7.1.5.2
7.2.2.2
8.0.2.1
References
Updated Jan 31, 2026 · Source: OSV.dev |
6.1.7.8
patch
Dependencies (6)
Changelog
Compare changes
|