CVE-2026-33174
HIGHRails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Title source: cnaDescription
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request with a large or unbounded Range header (e.g. `bytes=0-`) could cause the server to allocate memory proportional to the file size, possibly resulting in a DoS vulnerability through memory exhaustion. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-789
Status
published
Products (5)
rails/activestorage
< 7.2.3.1
rails/activestorage
>= 8.0.0.beta1, < 8.0.4.1
rails/activestorage
>= 8.1.0.beta1, < 8.1.2.1
rubygems/activestorage
8.1.0.beta1 - 8.1.2.1RubyGems
rubyonrails/rails
< 7.2.3.1
Published
Mar 24, 2026
Tracked Since
Mar 24, 2026