Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33658

Опубликовано: 26 мар. 2026
Источник: debian
EPSS Низкий

Описание

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:7.2.3.1+dfsg-1package
railsno-dsatrixiepackage
railsno-dsabookwormpackage
railspostponedbullseyepackage

Примечания

  • https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrg

  • Fixed by: https://github.com/rails/rails/commit/85ec5b1e00d3197d8c69a5e622e1b398a1b10b06 (v8.1.2.1)

  • Fixed by: https://github.com/rails/rails/commit/d7da4ef03f99035fba5add8828646f1e9173549c (v8.0.4.1)

  • Fixed by: https://github.com/rails/rails/commit/b8a1665824a43d71cd6406cf9adcae842ceb1c22 (v7.2.3.1)

EPSS

Процентиль: 36%
0.00434
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 7.5
redhat
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 6.5
nvd
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 6.5
github
4 месяца назад

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость компонента activesupport программной платформы Ruby on Rails, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 36%
0.00434
Низкий