<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:38:58.924749+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04602</id>
    <title>bdu:2021-04602</title>
    <updated>2026-10-04T15:38:58.930166+00:00</updated>
    <content>bdu:2021-04602</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-352</id>
    <title>certfr-2021-avi-352 — De multiples vulnérabilités ont été découvertes dans Ruby-on-rails.
Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-04T15:38:58.930202+00:00</updated>
    <content>certfr-2021-avi-352</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-352"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-44772</id>
    <title>cnvd-2021-44772</title>
    <updated>2026-10-04T15:38:58.930221+00:00</updated>
    <content>cnvd-2021-44772</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-44772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-23211</id>
    <title>EUVD-2026-23211</title>
    <updated>2026-10-04T15:38:58.930234+00:00</updated>
    <content>EUVD-2026-23211</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-23211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22903</id>
    <title>fkie_cve-2021-22903</title>
    <updated>2026-10-04T15:38:58.930244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts &lt;&lt; "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5hq2-xf89-9jxq</id>
    <title>GHSA-5hq2-xf89-9jxq — Possible Open Redirect Vulnerability in Action Pack</title>
    <updated>2026-10-04T15:38:58.930276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>There is a possible Open Redirect Vulnerability in Action Pack.</p>
<p>Versions Affected:  &gt;= v6.1.0.rc2
Not affected:       &lt; v6.1.0.rc2
Fixed Versions:     6.1.3.2</p>
<p>Impact
------
This is similar to CVE-2021-22881. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious
website.</p>
<p>Since rails/rails@9bc7ea5, strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, config.hosts &lt;&lt; "sub.example.com" to permit a request with a Host header value of sub-example.com.</p>
<p>Releases
--------
The fixed releases are available at the normal locations.</p>
<p>Workarounds
-----------
The following monkey patch put in an initializer can be used as a workaround.</p>
<p>```ruby
class ActionDispatch::HostAuthorization::Permissions
  def sanitize_string(host)
    if host.start_with?(".")
      /\A(.+\.)?#{Regexp.escape(host[1..-1])}\z/i
    else
      /\A#{Regexp.escape host}\z/i
    end
  end
end
```</p>
<p>Patches
-------
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>* 6-1-open-redirect.patch - Patch for 6.1 series</p>
<p>Please note that only the 6.1.Z, 6.0.Z, and 5.2.Z series are supported at present. Users of earlier unsupported releases are advised to upgrade as soon as possible as we cannot…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5hq2-xf89-9jxq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22903</id>
    <title>gsd-2021-22903</title>
    <updated>2026-10-04T15:38:58.930321+00:00</updated>
    <content>gsd-2021-22903</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22903</id>
    <title>UBUNTU-CVE-2021-22903</title>
    <updated>2026-10-04T15:38:58.930333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts &lt;&lt; "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341</id>
    <title>WID-SEC-W-2022-0341 — Ruby on Rails: Mehrere Schwachstellen</title>
    <updated>2026-10-04T15:38:58.930364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Informationen offenzulegen, einen Denial of Service Zustand auszulösen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341"/>
  </entry>
</feed>
