Vulnerabilidades em Rails
45 resultadosCVE-2026-33167LOWRails has a possible XSS vulnerability in its Action Pack debug exceptionsEPSS 0.4%CVE-2026-33173MEDIUMRails Active Storage has possible content type bypass via metadata in direct uploadsEPSS 0.4%CVE-2026-33170MEDIUMRails Active Support has a possible XSS vulnerability in SafeBuffer#%EPSS 0.3%CVE-2023-28362MEDIUMThe redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in thEPSS 0.3%CVE-2023-38037MEDIUMActiveSupport::EncryptedFile writes contents that will be encrypted to a
temporary file. The temporary file's permissions are defaulted toEPSS 0.3%