<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T00:57:36.583927+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2021-22903</id>
    <title>CVE-2021-22903</title>
    <updated>2026-10-07T00:57:36.612636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> https://github.com/rails/rails</p>
<p>The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts &lt;&lt; "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2021-22903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5hq2-xf89-9jxq</id>
    <title>GHSA-5hq2-xf89-9jxq — Possible Open Redirect Vulnerability in Action Pack</title>
    <updated>2026-10-07T00:57:36.612749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>There is a possible Open Redirect Vulnerability in Action Pack.</p>
<p>Versions Affected:  &gt;= v6.1.0.rc2
Not affected:       &lt; v6.1.0.rc2
Fixed Versions:     6.1.3.2</p>
<p>Impact
------
This is similar to CVE-2021-22881. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious
website.</p>
<p>Since rails/rails@9bc7ea5, strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, config.hosts &lt;&lt; "sub.example.com" to permit a request with a Host header value of sub-example.com.</p>
<p>Releases
--------
The fixed releases are available at the normal locations.</p>
<p>Workarounds
-----------
The following monkey patch put in an initializer can be used as a workaround.</p>
<p>```ruby
class ActionDispatch::HostAuthorization::Permissions
  def sanitize_string(host)
    if host.start_with?(".")
      /\A(.+\.)?#{Regexp.escape(host[1..-1])}\z/i
    else
      /\A#{Regexp.escape host}\z/i
    end
  end
end
```</p>
<p>Patches
-------
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>* 6-1-open-redirect.patch - Patch for 6.1 series</p>
<p>Please note that only the 6.1.Z, 6.0.Z, and 5.2.Z series are supported at present. Users of earlier unsupported releases are advised to upgrade as soon as possible as we cannot…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5hq2-xf89-9jxq"/>
  </entry>
</feed>
