
RubySec ➜ CVE-2026-33658 (activestorage): Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests https://rubysec.com/advisories/CVE-2026-33658/
Post summary
RubySec announces CVE-2026-33658 as a potential DoS vulnerability in Rails Active Storage’s proxy mode due to multi‑range requests; no PoC, exploit code, or active exploitation is reported.


