<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:03:50.638345+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-05203</id>
    <title>bdu:2021-05203</title>
    <updated>2026-10-04T00:03:50.909363+00:00</updated>
    <content>bdu:2021-05203</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-05203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-352</id>
    <title>certfr-2021-avi-352 — De multiples vulnérabilités ont été découvertes dans Ruby-on-rails.
Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-04T00:03:50.909401+00:00</updated>
    <content>certfr-2021-avi-352</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-352"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-23198</id>
    <title>EUVD-2026-23198</title>
    <updated>2026-10-04T00:03:50.909420+00:00</updated>
    <content>EUVD-2026-23198</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-23198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22904</id>
    <title>fkie_cve-2021-22904</title>
    <updated>2026-10-04T00:03:50.909432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7wjx-3g7j-8584</id>
    <title>GHSA-7wjx-3g7j-8584 — Possible DoS Vulnerability in Action Controller Token Authentication</title>
    <updated>2026-10-04T00:03:50.909460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>There is a possible DoS vulnerability in the Token Authentication logic in Action Controller.</p>
<p>Versions Affected:  &gt;= 4.0.0
Not affected:       &lt; 4.0.0
Fixed Versions:     6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6</p>
<p>Impact
------
Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.  Impacted code will look something like this:</p>
<p>```
class PostsController &lt; ApplicationController
  before_action :authenticate</p>
<p>private</p>
<p>def authenticate
    authenticate_or_request_with_http_token do |token, options|
      # ...
    end
  end
end
```</p>
<p>All users running an affected release should either upgrade or use one of the workarounds immediately.</p>
<p>Releases
--------
The fixed releases are available at the normal locations.</p>
<p>Workarounds
-----------
The following monkey patch placed in an initializer can be used to work around the issue:</p>
<p>```ruby
module ActionController::HttpAuthentication::Token
  AUTHN_PAIR_DELIMITERS = /(?:,|;|\t)/
end
```</p>
<p>Patches
-------
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>* 5-2-http-authentication-dos.patch - Patch for 5.2 series
* 6-0-http-authentication-dos.patch - Patch for 6.0 series
* 6-1-http-authentication-dos.patch - Patch for 6.1 series</p>
<p>Please note that only the 6.1.Z, 6.0.Z, and 5.2.Z series are supported at present. Users of earlier unsupported releases are…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7wjx-3g7j-8584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22904</id>
    <title>gsd-2021-22904</title>
    <updated>2026-10-04T00:03:50.909511+00:00</updated>
    <content>gsd-2021-22904</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1248</id>
    <title>OESA-2021-1248 — rubygem-actionpack security update</title>
    <updated>2026-10-04T00:03:50.909524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rubygem-actionpack</p>
<p>Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn't require a browser.

Security Fix(es):

The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.(CVE-2021-22904)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11317-1</id>
    <title>openSUSE-SU-2024:11317-1 — ruby2.7-rubygem-actionpack-5.2-5.2.6-1.2 on GA media</title>
    <updated>2026-10-04T00:03:50.909548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.7-rubygem-actionpack-5.2-5.2.6-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11317-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4702</id>
    <title>RHSA-2021:4702 — Red Hat Security Advisory: Satellite 6.10 Release</title>
    <updated>2026-10-04T00:03:50.909583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-ecdsa: Unexpected and  undocumented exceptions during signature decoding python-ecdsa: DER encoding is not being verified in signatures rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id rake: OS Command Injection via egrep in Rake::FileList guava: local information disclosure via temporary directory created with unsafe permissions PyYAML: incomplete fix for CVE-2020-1747 rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema Satellite: Azure compute resource secret_key leak to authenticated users foreman: possible man-in-the-middle in smart_proxy realm_freeipa Satellite: BMC controller credential leak via API python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack rails: Possible Denial of Service vulnerability in Action Dispatch rails: Possible DoS Vulnerability in Action Controller Token Authentication django: potential directory-traversal via uploaded files rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) django: Potential directory-traversal via uploaded files rubygem-addressable: ReDoS in templates django: Potential directory traversal via ``admindocs`` python-urllib3: ReDoS in the parsing of authority part of URL django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2108-1</id>
    <title>SUSE-SU-2022:2108-1 — Security update for rubygem-actionpack-5_1, rubygem-activesupport-5_1</title>
    <updated>2026-10-04T00:03:50.909636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-actionpack-5_1, rubygem-activesupport-5_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2108-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22904</id>
    <title>UBUNTU-CVE-2021-22904</title>
    <updated>2026-10-04T00:03:50.909665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341</id>
    <title>WID-SEC-W-2022-0341 — Ruby on Rails: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:03:50.909695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Informationen offenzulegen, einen Denial of Service Zustand auszulösen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341"/>
  </entry>
</feed>
