CVE-2026-33658
published 2026-03-26CVE-2026-33658: Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.43%
35.6th percentile
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1
Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | — | — |
| rails | activestorage | < 7.2.3.1 | 7.2.3.1 |
| rails | activestorage | — | — |
| rails | activestorage | — | — |
| rails | activestorage | >= 0 < 7.2.3.1 | 7.2.3.1 |
| rails | activestorage | >= 8.0.0 < 8.0.4.1 | 8.0.4.1 |
| rails | activestorage | >= 8.1.0 < 8.1.2.1 | 8.1.2.1 |
| rubyonrails | rails | < 7.2.3.1 | 7.2.3.1 |
| rubyonrails | rails | >= 8.0.0 < 8.0.4.1 | 8.0.4.1 |
| rubyonrails | rails | >= 8.1.0 < 8.1.2.1 | 8.1.2.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.3LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
activestorage Gem prior 7.2.3.1/8.0.4.1/8.1.2.1 on Rails allocation of resources (Nessus ID 304159)
vuldb·2026-05-06·CVSS 2.3
CVE-2026-33658 [LOW] activestorage Gem prior 7.2.3.1/8.0.4.1/8.1.2.1 on Rails allocation of resources (Nessus ID 304159)
A vulnerability identified as problematic has been detected in activestorage Gem on Rails. This impacts an unknown function. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2026-33658. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
OSV
CVE-2026-33658: Active Storage allows users to attach cloud and local files in Rails applications
osv·2026-03-26·CVSS 2.3
CVE-2026-33658 [LOW] CVE-2026-33658: Active Storage allows users to attach cloud and local files in Rails applications
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
GHSA
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
ghsa·2026-03-25
CVE-2026-33658 [LOW] CWE-770 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
### Impact
Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability.
### Releases
The fixed releases are available at the normal locations.
OSV
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
osv·2026-03-25
CVE-2026-33658 [LOW] Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
### Impact
Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability.
### Releases
The fixed releases are available at the normal locations.
Red Hat
rails: activestorage: Active Storage: Denial of Service via HTTP Range header processing
vendor_redhat·2026-03-26·CVSS 2.3
CVE-2026-33658 [LOW] CWE-770 rails: activestorage: Active Storage: Denial of Service via HTTP Range header processing
rails: activestorage: Active Storage: Denial of Service via HTTP Range header processing
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1
Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
A flaw was found in Active Storage, a component of Rails applications that handles file attachments. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP request with an excessive number of small byte ranges in the HTTP Ra
Debian
CVE-2026-33658: rails - Active Storage allows users to attach cloud and local files in Rails application...
vendor_debian·2026·CVSS 2.3
CVE-2026-33658 [LOW] CVE-2026-33658: rails - Active Storage allows users to attach cloud and local files in Rails application...
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33658 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-33658 [MEDIUM] CVE-2026-33658 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33658 :
Ruby vulnerability analysis and mitigation
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1
Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Source : NVD
## 2.3
Score
Published March 26, 2026
Severity LOW
CNA Score 2.3
Affected Technologies
Ruby
Rails
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.5
Exploitation
Bugzilla
CVE-2026-33658 rubygem-activestorage: Active Storage: Denial of Service via HTTP Range header processing [fedora-42]
bugzilla·2026-03-27·CVSS 2.3
CVE-2026-33658 [LOW] CVE-2026-33658 rubygem-activestorage: Active Storage: Denial of Service via HTTP Range header processing [fedora-42]
CVE-2026-33658 rubygem-activestorage: Active Storage: Denial of Service via HTTP Range header processing [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently
https://github.com/rails/rails/releases/tag/v7.2.3.1https://github.com/rails/rails/releases/tag/v8.0.4.1https://github.com/rails/rails/releases/tag/v8.1.2.1https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrghttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-33658.yml
2026-03-26
Published