Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33174

Опубликовано: 23 мар. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. bytes=0-) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

A flaw was found in Rails Active Storage. A remote attacker can exploit this vulnerability by sending a request with a large or unbounded Range header, such as bytes=0-, when files are served through Active Storage's proxy delivery mode. This action can cause the server to allocate memory proportional to the file size, potentially leading to a Denial of Service (DoS) due to memory exhaustion.

Отчет

This vulnerability is rated a Moderate by Red Hat. Successful exploitation of this vulnerability depends on specific application deployment conditions and configurations within Active Storage, including the use of proxy delivery mode and the presence of sufficiently large files accessible to the attacker. Additionally, practical exploitation may require knowledge of valid file URLs and the ability to bypass common infrastructure protections such as reverse proxies or request limiting. As a result, achieving a reliable denial-of-service condition is not guaranteed in all environments and may require non-trivial effort.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp20/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp21/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp21/zyncAffected
Red Hat 3scale API Management Platform 23scale-amp22/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp22/zyncAffected
Red Hat 3scale API Management Platform 23scale-amp24/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp24/zyncWill not fix
Red Hat 3scale API Management Platform 23scale-amp25/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp25/zyncAffected
Red Hat 3scale API Management Platform 23scale-amp26/systemWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2450544Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range header

EPSS

Процентиль: 46%
0.0061
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 7.5
nvd
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 7.5
debian
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails a ...

github
4 месяца назад

Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость компонента Active Storage программной платформы Ruby on Rails, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 46%
0.0061
Низкий

5.9 Medium

CVSS3