<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T17:09:20.620725+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-23633</id>
    <title>CVE-2022-23633 — Exposure of sensitive information in Action Pack</title>
    <updated>2026-10-05T17:09:20.653093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> rails</p>
<p>Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-23633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wh98-p28r-vrc9</id>
    <title>GHSA-wh98-p28r-vrc9 — Exposure of information in Action Pack</title>
    <updated>2026-10-05T17:09:20.653153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>### Impact</p>
<p>Under certain circumstances response bodies will not be closed, for example a [bug in a webserver](https://github.com/puma/puma/pull/2812) or a bug in a Rack middleware.  In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request.  This can lead to data being leaked to subsequent requests, especially when interacting with `ActiveSupport::CurrentAttributes`.</p>
<p>Upgrading to the FIXED versions of Rails will ensure mitigation of this issue even in the context of a buggy webserver or middleware implementation.</p>
<p>### Patches</p>
<p>This has been fixed in Rails 7.0.2.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2.</p>
<p>### Workarounds</p>
<p>Upgrading is highly recommended, but to work around this problem the following middleware can be used:</p>
<p>```ruby
class GuardedExecutor &lt; ActionDispatch::Executor
  def call(env)
    ensure_completed!
    super
  end</p>
<p>private</p>
<p>def ensure_completed!
      @executor.new.complete! if @executor.active?
    end
end</p>
<p># Ensure the guard is inserted before ActionDispatch::Executor
Rails.application.configure do
  config.middleware.swap ActionDispatch::Executor, GuardedExecutor, executor
end
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wh98-p28r-vrc9"/>
  </entry>
</feed>
