Security: rails/rails
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Possible arbitrary file read and remote code execution in Active Storage variant processingGHSA-xr9x-r78c-5hrm published
Jul 29, 2026 by byrootCritical -
Possible glob injection in Active Storage DiskServiceGHSA-73f9-jhhh-hr5m published
Mar 23, 2026 by jhawthornLow -
Possible path traversal in Active Storage DiskServiceGHSA-9xrj-h377-fr87 published
Mar 23, 2026 by jhawthornLow -
Possible DoS vulnerability in Active Storage proxy mode via multi-range requestsGHSA-p9fm-f462-ggrg published
Mar 23, 2026 by jhawthornLow -
Possible DoS vulnerability in Active Support number helpersGHSA-2j26-frm8-cmj9 published
Mar 23, 2026 by jhawthornLow -
Possible DoS vulnerability in Active Storage proxy mode via Range requestsGHSA-r46p-8f7g-vvvg published
Mar 23, 2026 by jhawthornLow -
Insufficient filtering of metadata in Active Storage direct uploadsGHSA-qcfx-2mfw-w4cg published
Mar 23, 2026 by jhawthornLow -
Possible XSS vulnerability in SafeBuffer#% in Active SupportGHSA-89vf-4333-qx8v published
Mar 23, 2026 by jhawthornLow -
Possible ReDoS vulnerability in number_to_delimited in Active SupportGHSA-cg4j-q9v8-6v38 published
Mar 23, 2026 by jhawthornLow -
Possible XSS vulnerability in Action View tag helpersGHSA-v55j-83pf-r9cq published
Mar 23, 2026 by jhawthornLow