CVE-2026-33658

medium
Published 2026-03-25 · Modified 2026-05-06
CVSS v3
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk
6.5

Description

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-33658

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrg

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/rails/rails/releases/tag/v8.1.2.1

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/rails/rails/releases/tag/v8.0.4.1

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/rails/rails/releases/tag/v7.2.3.1

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed2:7.2.3.1+dfsg-1
debian debiansidfixed2:7.2.3.1+dfsg-1
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactivestorage<~> 7.2.3, >= 7.2.3.1~> 7.2.3, >= 7.2.3.1
ruby RubyGemsactivestorage>=8.1.0,<8.1.2.18.1.2.1
ruby RubyGemsactivestorage>=8.0.0,<8.0.4.18.0.4.1
ruby RubyGemsactivestorage<7.2.3.17.2.3.1
ruby RUBYGEMSactivestorage< 7.2.3.17.2.3.1
ruby RUBYGEMSactivestorage>= 8.0.0, < 8.0.4.18.0.4.1
ruby RUBYGEMSactivestorage>= 8.1.0, < 8.1.2.18.1.2.1

Application impact

VendorProductVersionsFixed
rubyonrailsrails{"endExcluding":"7.2.3.1"}7.2.3.1

References

CWEs

CWE-770

Verify integrity in audit chain (admin only). AS-IS.