VDB
CVE-2026-33658
CVE-2026-33658
PUBLISHED
CVSS 2.299999952316284 LOW
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
EPSS 0.02% · 6.0th percentile
Risk Scores
CVSS v4.0
2.299999952316284
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
EPSS Score
0.02%
6.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| rails | activestorage | *, >= 8.1.0, < 8.1.2.1, * |
| Azure | storage | |
| rubyonrails | rails | 8.0.0, 8.1.0, 0 |
| RubyGems | activestorage | 8.0.0, 8.1.0, 0 |
| rails | actionpack | * |
Timeline
- Mar 23, 2026 PoC Published
- Mar 24, 2026 CVE Published
- Mar 24, 2026 PoC Published
- Mar 24, 2026 PoC Published
- Mar 26, 2026 Security Advisory
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- May 6, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
References
- https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrg url
- https://github.com/rails/rails/releases/tag/v7.2.3.1 url
- https://github.com/rails/rails/releases/tag/v8.0.4.1 url
- https://github.com/rails/rails/releases/tag/v8.1.2.1 url
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-33658.yml url
- https://nvd.nist.gov/vuln/detail/CVE-2026-33658 advisory
- https://github.com/rails/rails package
- https://discuss.rubyonrails.org/t/cve-2026-33168-possible-xss-vulnerability-in-action-view-tag-helpers/90912 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33169-possible-redos-vulnerability-in-number-to-delimited-in-active-support/90911 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33170-possible-xss-vulnerability-in-safebuffer-in-active-support/90910 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33167-possible-xss-vulnerability-in-action-pack-debug-exceptions/90913 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33658-possible-dos-vulnerability-in-active-storage-proxy-mode-via-multi-range-requests/90906 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33174-possible-dos-vulnerability-in-active-storage-proxy-mode-via-range-requests/90908 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33202-possible-glob-injection-in-active-storage-diskservice/90903 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33195-possible-path-traversal-in-active-storage-diskservice/90904 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33173-insufficient-filtering-of-metadata-in-active-storage-direct-uploads/90909 advisory
- https://discuss.rubyonrails.org/t/cve-2026-33176-possible-dos-vulnerability-in-active-support-number-helpers/90907 advisory
- https://github.com/rails/rails/security/advisories/GHSA-pgm4-439c-5jp6 url
- https://github.com/rails/rails/commit/6752711c8c31d79ba50d13af6a6698a3b85415e0 url