CVE-2026-33168Disclosure

LOWCVSS 2.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-23); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-23: 2Mentions · 2026-03-24: 2Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 103-2303-24
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-232
Disclosure1Patch1
2026-03-242
Disclosure1General1
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33168 Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is … https://www.cve.org/CVERecord?id=CVE-2026-33168 ----- Traducción: CVE-2026-33168 Act… http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE‑2026‑33168, a Rails Action View vulnerability affecting certain older versions, providing brief technical context but no exploit or mitigation details.

    0000029
    60 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33168 Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is … https://www.cve.org/CVERecord?id=CVE-2026-33168

    Post summary

    The content merely cites CVE-2026-33168 with a link, lacking details on exploitation, patches, or technical specifics.

    00000169
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33168 - Rails has a possible XSS vulnerability in its Action View tag helpers Intel Report: https://ift.tt/ovIKQYP

    Post summary

    A possible XSS vulnerability (CVE-2026-33168) in Rails Action View tag helpers has been identified; no exploit, patch, or PoC details are provided in the text.

    0000036
    289 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Ruby on Rails v7.2.3.1 がリリースされました。 📦 種別: patch ✨ 主な変更点: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) ⚠️ 破壊的変更: • `DiskService#delete_prefixed`の変更により、既存のグロブメタ文字展開に依存するコードは動作しなくなります。 🔧 重要な修正: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) #GitHub #Release #Ruby on Rails

    Post summary

    Ruby on Rails v7.2.3.1 is released as a patch update addressing multiple CVEs, with detailed fix notes and a note on breaking changes.

    0000036
    2 followersView on X

Explore more