Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

rails — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in rails, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Rails framework, developed by 37signals, focusing on known security weaknesses within the product. It collects advisories related to cross-site scripting, remote code execution, and authorization flaws, covering historical records spanning several years of updates. Readers can use this resource to track the vendor's security advisories, understand specific weakness classes like injection or authentication bypass, and review the complete vulnerability history for the Rails product.

Vendor: rails

CVE ID Title CVSS Severity Published
CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing CWE-1188 9.5 Critical 2026-07-30
CVE-2025-55193 Active Record logging vulnerable to ANSI escape injection CWE-150 5.3AI Medium AI 2025-08-13
CVE-2024-54133 Possible Content Security Policy bypass in Action Dispatch CWE-79 6.1 - 2024-12-10
CVE-2024-47889 Action Mailer has possible ReDoS vulnerability in block_format CWE-1333 7.5 - 2024-10-16
CVE-2024-47888 Action Text has possible ReDoS vulnerability in plain_text_for_blockquote_node CWE-1333 7.5 - 2024-10-16
CVE-2024-47887 Action Controller has possible ReDoS vulnerability in HTTP Token authentication CWE-1333 7.5 - 2024-10-16
CVE-2024-41128 Action Dispatch has possible ReDoS vulnerability in query parameter filtering CWE-770 7.5 - 2024-10-16
CVE-2024-32464 ActionText ContentAttachment can Contain Unsanitized HTML CWE-80 6.1 Medium 2024-06-04
CVE-2024-28103 Action Pack is missing security headers on non-HTML responses CWE-20 5.4 Medium 2024-06-04
CVE-2024-26144 Possible Sensitive Session Information Leak in Active Storage CWE-200 5.3 Medium 2024-02-27
CVE-2024-26143 Rails Possible XSS Vulnerability in Action Controller CWE-79 6.1 Medium 2024-02-27
CVE-2024-26142 Rails possible ReDoS vulnerability in Accept header parsing in Action Dispatch CWE-1333 7.5 High 2024-02-27
CVE-2022-23633 Exposure of sensitive information in Action Pack CWE-200 7.4 High 2022-02-11
CVE-2011-1497 Rails 跨站脚本漏洞 CWE-79 6.1 - 2021-10-19
CVE-2010-3299 Ruby on Rails 安全漏洞 5.3 - 2019-11-12

All 15 known CVE vulnerabilities affecting rails with full Chinese analysis, references, and POCs where available.