<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:55:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10713</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10713</link>
      <description>bdu:2026-10713</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10713</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0948 — Une vulnérabilité a été découverte dans Ruby on Rails activestorage. Elle permet à un attaquant de provoquer une exécut…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0948</link>
      <description>certfr-2026-avi-0948</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0948</guid>
    </item>
    <item>
      <title>EUVD-2026-348505</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348505</link>
      <description>EUVD-2026-348505</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348505</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66066</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66066</link>
      <description>&lt;p&gt;Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66066</guid>
    </item>
    <item>
      <title>GHSA-xr9x-r78c-5hrm — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xr9x-r78c-5hrm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activestorage&lt;/p&gt;
&lt;p&gt;### Impact
In its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds `secret_key_base` and often credentials for external systems, which
may in turn allow escalation to remote code execution or lateral movement to those systems.&lt;/p&gt;
&lt;p&gt;### Details
libvips reads and writes file formats through &amp;#34;loaders&amp;#34; and &amp;#34;savers&amp;#34; (or more generally
&amp;#34;operations&amp;#34;), many of which are backed by third-party libraries. It marks some of these operations
as &amp;#34;unfuzzed&amp;#34;, meaning they are unsafe for untrusted content, and several handle formats unrelated
to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload
a crafted file and cause a variant to be generated from it may be able to invoke one.&lt;/p&gt;
&lt;p&gt;We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause
disclosure of the contents of arbitrary files accessible on the filesystem of the targeted
application. One specific attack chain has been reported to us (see &amp;#34;Disclosure&amp;#34; below), but we do
not assume it is the only one that exists.&lt;/p&gt;
&lt;p&gt;### Affected applications
An application is affected if it meets all of these requirements:
- Uses libvips for Active Storage image processing. This is `config.active_storage.variant_processor = :vips`,
  which `load_defaults 7.0` set and no later default has changed.
- Allows image…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activestorage&lt;/p&gt;
&lt;p&gt;### Impact
In its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds `secret_key_base` and often credentials for external systems, which
may in turn allow escalation to remote code execution or lateral movement to those systems.&lt;/p&gt;
&lt;p&gt;### Details
libvips reads and writes file formats through &amp;#34;loaders&amp;#34; and &amp;#34;savers&amp;#34; (or more generally
&amp;#34;operations&amp;#34;), many of which are backed by third-party libraries. It marks some of these operations
as &amp;#34;unfuzzed&amp;#34;, meaning they are unsafe for untrusted content, and several handle formats unrelated
to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload
a crafted file and cause a variant to be generated from it may be able to invoke one.&lt;/p&gt;
&lt;p&gt;We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause
disclosure of the contents of arbitrary files accessible on the filesystem of the targeted
application. One specific attack chain has been reported to us (see &amp;#34;Disclosure&amp;#34; below), but we do
not assume it is the only one that exists.&lt;/p&gt;
&lt;p&gt;### Affected applications
An application is affected if it meets all of these requirements:
- Uses libvips for Active Storage image processing. This is `config.active_storage.variant_processor = :vips`,
  which `load_defaults 7.0` set and no later default has changed.
- Allows image…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xr9x-r78c-5hrm</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-66066</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66066</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66066</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2574 — Ruby on Rails: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2574</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um Informationen offenzulegen, was möglicherweise zur Remote-Codeausführung oder zu lateraler Bewegung führen kann.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um Informationen offenzulegen, was möglicherweise zur Remote-Codeausführung oder zu lateraler Bewegung führen kann.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2574</guid>
    </item>
  </channel>
</rss>
