CVE-2026-33174Patch(rubyonrails / rails)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch rubyonrails rails systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rails

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-24)
  • 5 total mentions across 2 days

Affected systems

Products
rails

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-23: 1Mentions · 2026-03-24: 4Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 2Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 103-2303-24
Signal classification2 categories
Patch
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-231
Patch1
2026-03-244
General2Patch2
Full discourse5 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 Attention Rails developers! CVE-2026-33174 could lead to DoS via large HTTP Range headers, causing memory exhaustion. 💥 Update to Rails versions 8.1.2.1, 8.0.4.1, or 7.2.3.1 ASAP! Keep your apps safe! 🔒 👉 Learn more: https://www.tenable.com/cve/CVE-2026-33174 #Cybersecurity #Rails #DevOps

    Post summary

    The post announces CVE-2026-33174, explains it causes a DoS via large HTTP Range headers, and prompts developers to update to specific Rails versions.

    0000031
    258 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33174 📊 Severity: 6.6 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33174 #CVE-2026-33174 #CVE #Medium #CyberSecurity #InfoSec https://t.co/mrH4XeGk62

    Post summary

    The tweet simply announces CVE‑2026‑33174 with its severity rating and a link to the NVD entry, offering no further exploitation or remediation details.

    0000028
    111 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-33174 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active … https://www.cve.org/CVERecord?id=CVE-2026-33174 ----- Traducción: CVE-2026-33174 Act… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-33174, notes affected Rails versions that are presumably patched, but offers no PoC, exploit, active exploitation evidence, or detailed technical data.

    0000023
    60 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33174 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active … https://www.cve.org/CVERecord?id=CVE-2026-33174

    Post summary

    The excerpt notes affected Ruby on Rails versions for CVE‑2026‑33174 but offers no detail about exploitation, mitigation, or technical nature of the flaw.

    00000159
    56.8K followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Ruby on Rails v7.2.3.1 がリリースされました。 📦 種別: patch ✨ 主な変更点: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) ⚠️ 破壊的変更: • `DiskService#delete_prefixed`の変更により、既存のグロブメタ文字展開に依存するコードは動作しなくなります。 🔧 重要な修正: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) #GitHub #Release #Ruby on Rails

    Post summary

    This post announces Ruby on Rails v7.2.3.1, a patch release that addresses multiple CVEs in Active Support, Action View and Active Storage, but contains no PoCs, exploit code, or reports of active exploitation.

    0000036
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprubyonrailsrails---

Explore more