
CVE-2026-33170 is fascinating because it breaks Rails' own XSS protection system. SafeBuffer#% operator fails to propagate the html_unsafe flag when creating new buffers, so content that should be escaped gets marked as safe. It's a flaw in the security mechanism itself, not just another injection point. Rails apps using SafeBuffer with the % operator for formatting could be exposing XSS vulnerabilities without realising their protection layer is compromised.
Post summary
CVE-2026-33170 reveals that Rails' SafeBuffer#% operator incorrectly propagates the html_unsafe flag, letting malicious content escape XSS protection and exposing applications to cross‑site scripting attacks.




