Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

rails — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in rails, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the open-source Ruby on Rails web framework, focusing on Common Weakness Enumerations (CWE) and Common Vulnerabilities and Exposures (CVE). It collects detailed reports on security flaws ranging from remote code execution and injection attacks to information disclosure and cross-site scripting issues discovered in Rails applications and the core framework itself. The data covers vulnerabilities identified from the early releases of the framework through to recent updates, ensuring a comprehensive historical perspective on the security landscape surrounding this technology. Here, you can track security advisories released by the Rails core team and third-party vendors, allowing developers to stay informed about critical patches and mitigation strategies. The page enables users to understand specific weakness classes by analyzing patterns and contexts in which they occur within Rails-based architectures, helping security professionals identify systemic risks. Additionally, it provides a searchable history of vulnerabilities for the product, facilitating the review of past incidents to assess the long-term security posture and remediation efficiency of the framework. This centralized view supports better risk management and compliance efforts for organizations relying on Rails, offering clear insights into the nature, severity, and resolution of reported issues without the noise of unrelated data.

Vendor: rails

CVE IDTitleCVSSSeverityPublished
CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing CWE-1188 9.5 Critical2026-07-30
CVE-2025-55193 Active Record logging vulnerable to ANSI escape injection CWE-150 5.3AIMediumAI2025-08-13
CVE-2024-54133 Possible Content Security Policy bypass in Action Dispatch CWE-79 6.1 -2024-12-10
CVE-2024-47889 Action Mailer has possible ReDoS vulnerability in block_format CWE-1333 7.5 -2024-10-16
CVE-2024-47888 Action Text has possible ReDoS vulnerability in plain_text_for_blockquote_node CWE-1333 7.5 -2024-10-16
CVE-2024-47887 Action Controller has possible ReDoS vulnerability in HTTP Token authentication CWE-1333 7.5 -2024-10-16
CVE-2024-41128 Action Dispatch has possible ReDoS vulnerability in query parameter filtering CWE-770 7.5 -2024-10-16
CVE-2024-32464 ActionText ContentAttachment can Contain Unsanitized HTML CWE-80 6.1 Medium2024-06-04
CVE-2024-28103 Action Pack is missing security headers on non-HTML responses CWE-20 5.4 Medium2024-06-04
CVE-2024-26144 Possible Sensitive Session Information Leak in Active Storage CWE-200 5.3 Medium2024-02-27
CVE-2024-26143 Rails Possible XSS Vulnerability in Action Controller CWE-79 6.1 Medium2024-02-27
CVE-2024-26142 Rails possible ReDoS vulnerability in Accept header parsing in Action Dispatch CWE-1333 7.5 High2024-02-27
CVE-2022-23633 Exposure of sensitive information in Action Pack CWE-200 7.4 High2022-02-11
CVE-2011-1497 Rails 跨站脚本漏洞 CWE-79 6.1 -2021-10-19
CVE-2010-3299 Ruby on Rails 安全漏洞 5.3 -2019-11-12

All 15 known CVE vulnerabilities affecting rails with full Chinese analysis, references, and POCs where available.