CVE-2026-33658

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*

History

30 Apr 2026, 19:02

Type Values Removed Values Added
References () https://github.com/rails/rails/releases/tag/v7.2.3.1 - () https://github.com/rails/rails/releases/tag/v7.2.3.1 - Product, Release Notes
References () https://github.com/rails/rails/releases/tag/v8.0.4.1 - () https://github.com/rails/rails/releases/tag/v8.0.4.1 - Product, Release Notes
References () https://github.com/rails/rails/releases/tag/v8.1.2.1 - () https://github.com/rails/rails/releases/tag/v8.1.2.1 - Product, Release Notes
References () https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrg - () https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrg - Vendor Advisory
References () https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-33658.yml - () https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-33658.yml - Third Party Advisory
CPE cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
First Time Rubyonrails
Rubyonrails rails
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) Active Storage permite a los usuarios adjuntar archivos en la nube y locales en aplicaciones Rails. Antes de las versiones 8.1.2.1, 8.0.4.1 y 7.2.3.1, el controlador proxy de Active Storage no limita el número de rangos de bytes en un encabezado HTTP Range. Una solicitud con miles de rangos pequeños causa un uso desproporcionado de la CPU en comparación con una solicitud normal para el mismo archivo, lo que posiblemente resulte en una vulnerabilidad de DoS. Las versiones 8.1.2.1, 8.0.4.1 y 7.2.3.1 contienen un parche.

26 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 22:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33658

Mitre link : CVE-2026-33658

CVE.ORG link : CVE-2026-33658


JSON object : View

Products Affected

rubyonrails

  • rails
CWE
CWE-770

Allocation of Resources Without Limits or Throttling