CVE-2026-33176Patch(rubyonrails / rails)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch rubyonrails rails systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rails

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-24)
  • 4 total mentions across 2 days

Affected systems

Products
rails

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-23: 1Mentions · 2026-03-24: 3Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 103-2303-24
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-231
Patch1
2026-03-243
Disclosure1General1Patch1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33176 📊 Severity: 6.6 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33176 #CVE-2026-33176 #CVE #Medium #CyberSecurity #InfoSec https://t.co/bl1llgrNQt

    Post summary

    The tweet announces CVE-2026-33176, states its severity and risk level, and supplies a link to the NVD page.

    1000032
    111 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    ⚠️ Attention Rails devs! CVE-2026-33176 poses a risk of DoS due to memory overload from big scientific numbers in Active Support. Update your Rails ASAP to versions 8.1.2.1, 8.0.4.1, or 7.2.3.1! 🛡️ Protect your apps! 🔗 https://www.tenable.com/cve/CVE-2026-33176 #Rails #Cybersecurity #CVE

    Post summary

    The post is a patch announcement warning Rails developers of a DoS vulnerability (CVE‑2026‑33176) and recommending specific version upgrades.

    0000028
    258 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33176 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active … https://www.cve.org/CVERecord?id=CVE-2026-33176

    Post summary

    The entry only records CVE‑2026‑33176 and lists affected Rails versions, providing no additional exploitation, patch, or technical details.

    00000180
    56.8K followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Ruby on Rails v7.2.3.1 がリリースされました。 📦 種別: patch ✨ 主な変更点: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) ⚠️ 破壊的変更: • `DiskService#delete_prefixed`の変更により、既存のグロブメタ文字展開に依存するコードは動作しなくなります。 🔧 重要な修正: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) #GitHub #Release #Ruby on Rails

    Post summary

    Ruby on Rails v7.2.3.1 is a patch release that addresses multiple CVEs, providing fixes for path traversal, glob injection, and other issues.

    0000036
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprubyonrailsrails---

Explore more