About the Security Announcements category | | 1 | 4420 | February 10, 2021 |
[CVE-2025-24293] Active Storage allowed transformation methods potentially unsafe | | 0 | 1038 | August 13, 2025 |
[CVE-2025-55193] ANSI escape injection in Active Record logging | | 0 | 825 | August 13, 2025 |
[CVE-2024-47889] Possible ReDoS vulnerability in block_format in Action Mailer | | 0 | 853 | October 15, 2024 |
[CVE-2024-54133] Possible Content Security Policy bypass in Action Dispatch | | 0 | 1277 | December 10, 2024 |
Rails-html-sanitizer v1.6.1 addresses multiple CVEs | | 0 | 521 | December 2, 2024 |
[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text | | 0 | 556 | October 15, 2024 |
[CVE-2024-41128] Possible ReDoS vulnerability in query parameter filtering in Action Dispatch | | 0 | 781 | October 15, 2024 |
[CVE-2024-47887] Possible ReDoS vulnerability in HTTP Token authentication in Action Controller | | 0 | 874 | October 15, 2024 |
[CVE-2024-32464] ActionText ContentAttachment's can Contain Unsanitized HTML | | 0 | 2298 | June 4, 2024 |
[CVE-2024-28103] Permissions-Policy is Only Served on HTML Content-Type | | 0 | 1903 | June 4, 2024 |
XSS Vulnerabilities in Trix Editor | | 0 | 1818 | May 17, 2024 |
Possible XSS Vulnerability in Action Controller | | 2 | 7975 | February 27, 2024 |
Possible Denial of Service Vulnerability in Rack Header Parsing | | 0 | 4587 | February 21, 2024 |
Possible ReDoS vulnerability in Accept header parsing in Action Dispatch | | 0 | 3886 | February 21, 2024 |
Denial of Service Vulnerability in Rack Content-Type Parsing | | 0 | 4943 | February 21, 2024 |
Possible Sensitive Session Information Leak in Active Storage | | 0 | 5439 | February 21, 2024 |
Possible DoS Vulnerability with Range Header in Rack | | 0 | 4649 | February 21, 2024 |
[CVE-2023-38037] Possible File Disclosure of Locally Encrypted Files | | 0 | 6171 | August 22, 2023 |
[CVE-2023-28362] Possible XSS via User Supplied Values to redirect_to | | 0 | 12248 | June 26, 2023 |
[CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID | | 0 | 6048 | January 17, 2023 |
[CVE-2022-44572] Possible Denial of Service Vulnerability in Rack's RFC2183 boundary parsing | | 0 | 4547 | January 17, 2023 |
[CVE-2022-44571] Possible Denial of Service Vulnerability in Rack Content-Disposition parsing | | 0 | 6843 | January 17, 2023 |
[CVE-2023-27539] Possible Denial of Service Vulnerability in Rack's header parsing | | 0 | 6978 | March 13, 2023 |
[CVE-2023-27531] Possible Deserialization of Untrusted Data vulnerability in Kredis JSON | | 0 | 4033 | March 13, 2023 |
[CVE-2023-28120] Possible XSS Security Vulnerability in SafeBuffer#bytesplice | | 0 | 8381 | March 13, 2023 |
[CVE-2023-23913] DOM Based Cross-site Scripting in rails-ujs for contenteditable HTML Elements | | 0 | 6506 | March 13, 2023 |
[CVE-2023-27530] Possible DoS Vulnerability in Multipart MIME parsing | | 0 | 10540 | March 2, 2023 |
[CVE-2022-44570] Possible Denial of Service Vulnerability in Rack's Range header parsing | | 0 | 7245 | January 17, 2023 |
[CVE-2023-22794] SQL Injection Vulnerability via ActiveRecord comments | | 0 | 31112 | January 17, 2023 |