Rails
26 CVEs tracked since 2022. Since Dec 2022, none of them reached CISA KEV.
Rails CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-12 | 4 | 0 |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | 6 | 0 |
| 2025-01 | 6 | 0 |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | 10 | 0 |
Products
The products that kept showing up in Rails's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Rails.
- CVE-2026-73648rails-html-sanitizer: Possible XSS vulnerability with certain configurations—
- CVE-2026-66066Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing—
- CVE-2026-33658Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests6.5
- CVE-2026-33202Rails Active Storage has possible glob injection in its DiskService9.1
- CVE-2026-33195Rails Active Storage has possible Path Traversal in DiskService9.8
- CVE-2026-33176Rails Active Support has a possible DoS vulnerability in its number helpers7.5
- CVE-2026-33174Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests7.5
- CVE-2026-33173Rails Active Storage has possible content type bypass via metadata in direct uploads5.3
- CVE-2026-33170Rails Active Support has a possible XSS vulnerability in SafeBuffer#%6.1
- CVE-2026-33169Rails Active Support has a possible ReDoS vulnerability in number_to_delimited5.3
- CVE-2026-33168Rails has a possible XSS vulnerability in its Action View tag helpers6.5
- CVE-2026-33167Rails has a possible XSS vulnerability in its Action Pack debug exceptions6.1
- CVE-2025-24293# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. Th...8.1
- CVE-2025-55193Active Record logging vulnerable to ANSI escape injection—
- CVE-2023-38037ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's ...5.5
The record
- Peak rank
- #113 in Dec 2024
- Busiest month shown
- Mar 2026, 10 CVEs
- Months with a KEV entry
- 0 since Dec 2022
- Monthly snapshots
- 4 since 2022