<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:43:10.173369+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2021-22904</id>
    <title>CVE-2021-22904</title>
    <updated>2026-10-06T21:43:10.203267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> https://github.com/rails/rails</p>
<p>The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2021-22904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7wjx-3g7j-8584</id>
    <title>GHSA-7wjx-3g7j-8584 — Possible DoS Vulnerability in Action Controller Token Authentication</title>
    <updated>2026-10-06T21:43:10.203320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>There is a possible DoS vulnerability in the Token Authentication logic in Action Controller.</p>
<p>Versions Affected:  &gt;= 4.0.0
Not affected:       &lt; 4.0.0
Fixed Versions:     6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6</p>
<p>Impact
------
Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.  Impacted code will look something like this:</p>
<p>```
class PostsController &lt; ApplicationController
  before_action :authenticate</p>
<p>private</p>
<p>def authenticate
    authenticate_or_request_with_http_token do |token, options|
      # ...
    end
  end
end
```</p>
<p>All users running an affected release should either upgrade or use one of the workarounds immediately.</p>
<p>Releases
--------
The fixed releases are available at the normal locations.</p>
<p>Workarounds
-----------
The following monkey patch placed in an initializer can be used to work around the issue:</p>
<p>```ruby
module ActionController::HttpAuthentication::Token
  AUTHN_PAIR_DELIMITERS = /(?:,|;|\t)/
end
```</p>
<p>Patches
-------
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>* 5-2-http-authentication-dos.patch - Patch for 5.2 series
* 6-0-http-authentication-dos.patch - Patch for 6.0 series
* 6-1-http-authentication-dos.patch - Patch for 6.1 series</p>
<p>Please note that only the 6.1.Z, 6.0.Z, and 5.2.Z series are supported at present. Users of earlier unsupported releases are…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7wjx-3g7j-8584"/>
  </entry>
</feed>
