activestorage
RubyGems11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting activestoragepage 1 of 1
- CVE-2018-16477MEDIUMCVSS 6.5EG 6.5fixed in 5.2.1.12018-11-30
vulnerable: 5.2.0, 5.2.1, 5.2.1.rc1
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and have them executed in…
- CVE-2020-8162HIGHCVSS 7.5EG 7.5fixed in 5.2.4.3 or 6.0.3.1, by version range2020-06-19
vulnerable: 6.0.0 ... 6.0.3.rc1 (10 versions)
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload …
- CVE-2022-21831CRITICALCVSS 9.8EG 9.8fixed in 5.2.6.3, 6.0.4.7, 6.1.4.7 or 7.0.2.3, by version range2022-05-26
vulnerable: 7.0.0, 7.0.1, 7.0.2, 7.0.2.1, 7.0.2.2
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
- CVE-2024-26144MEDIUMCVSS 5.3EG 5.3fixed in 6.1.7.7 or 7.0.8.1, by version range2024-02-27
vulnerable: 7.0.0 ... 7.0.8 (20 versions)
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when ser…
- CVE-2025-24293HIGHCVSS 8.1EG 8.1fixed in 8.0.2.1, 7.2.2.2 or 7.1.5.2, by version range2026-01-30
vulnerable: 5.2.0 ... 7.1.5.1 (142 versions)
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three meth…
- CVE-2026-33173MEDIUMCVSS 5.3EG 5.3fixed in 8.1.2.1, 8.0.4.1 or 7.2.3.1, by version range2026-03-24
vulnerable: 0.1 ... 7.2.3 (161 versions)
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because i…
- CVE-2026-33174HIGHCVSS 7.5EG 7.5fixed in 8.1.2.1, 8.0.4.1 or 7.2.3.1, by version range2026-03-24
vulnerable: 0.1 ... 7.2.3 (161 versions)
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requ…
- CVE-2026-33195CRITICALCVSS 9.8EG 9.8fixed in 8.1.2.1, 8.0.4.1 or 7.2.3.1, by version range2026-03-24
vulnerable: 0.1 ... 7.2.3 (161 versions)
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within …
- CVE-2026-33202CRITICALCVSS 9.1EG 9.1fixed in 8.1.2.1, 8.0.4.1 or 7.2.3.1, by version range2026-03-24
vulnerable: 0.1 ... 7.2.3 (161 versions)
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glo…
- CVE-2026-33658MEDIUMCVSS 6.5EG 6.5fixed in 8.1.2.1, 8.0.4.1 or 7.2.3.1, by version range2026-03-26
vulnerable: 0.1 ... 7.2.3 (161 versions)
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A reques…
- CVE-2026-66066CRITICALCVSS 9.5EG 9.5fixed in 7.2.3.2, 8.0.5.1 or 8.1.3.1, by version range2026-07-30
vulnerable: 8.1.0 ... 8.1.3 (7 versions)
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to…
Check whether activestorage is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for activestorage CVEs against the assets you own.
Book a Demo →