DEBIAN-CVE-2026-33168

Source
https://security-tracker.debian.org/tracker/CVE-2026-33168
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33168.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-33168
Upstream
Published
2026-03-23T23:17:12.873Z
Modified
2026-04-16T17:03:18.183184Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

References

Affected packages

Debian:11 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:6.*
2:6.0.3.7+dfsg-2
2:6.0.3.7+dfsg-2+deb11u1
2:6.0.3.7+dfsg-2+deb11u2
2:6.0.3.7+dfsg-2+deb11u3
2:6.0.3.7+dfsg-2+deb11u4
2:6.0.3.7+dfsg-3
2:6.1.4+dfsg-1
2:6.1.4+dfsg-2
2:6.1.4+dfsg-3
2:6.1.4+dfsg-4
2:6.1.4.1+dfsg-1
2:6.1.4.1+dfsg-2
2:6.1.4.1+dfsg-3
2:6.1.4.1+dfsg-4
2:6.1.4.1+dfsg-5
2:6.1.4.1+dfsg-6
2:6.1.4.1+dfsg-7
2:6.1.4.1+dfsg-8
2:6.1.4.6+dfsg-1
2:6.1.4.6+dfsg-2
2:6.1.4.6+dfsg-3
2:6.1.4.7+dfsg-1
2:6.1.4.7+dfsg-2
2:6.1.6.1+dfsg-1
2:6.1.6.1+dfsg-2
2:6.1.6.1+dfsg-3
2:6.1.6.1+dfsg-4
2:6.1.7+dfsg-1
2:6.1.7+dfsg-2
2:6.1.7+dfsg-3~bpo11+1
2:6.1.7+dfsg-3~bpo11+2
2:6.1.7+dfsg-3
2:6.1.7.3+dfsg-1~bpo11+1
2:6.1.7.3+dfsg-1
2:6.1.7.3+dfsg-2~deb12u1
2:6.1.7.3+dfsg-2
2:6.1.7.3+dfsg-3
2:6.1.7.3+dfsg-4
2:6.1.7.3+dfsg-5
2:6.1.7.3+dfsg-6
2:6.1.7.3+dfsg-7~exp1
2:6.1.7.3+dfsg-7
2:6.1.7.3+dfsg-8
2:6.1.7.3+dfsg-9
2:6.1.7.3+dfsg-10
2:6.1.7.3+dfsg-11
2:6.1.7.3+dfsg-12
2:6.1.7.3+dfsg-13
2:6.1.7.10+dfsg-1~deb12u1
2:6.1.7.10+dfsg-1~deb12u2
2:7.*
2:7.2.2.1+dfsg-1~exp1
2:7.2.2.1+dfsg-1~exp2
2:7.2.2.1+dfsg-1~exp3
2:7.2.2.1+dfsg-1~exp4
2:7.2.2.1+dfsg-1~exp6
2:7.2.2.1+dfsg-1
2:7.2.2.1+dfsg-2
2:7.2.2.1+dfsg-3
2:7.2.2.1+dfsg-4
2:7.2.2.1+dfsg-5
2:7.2.2.1+dfsg-6
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3
2:7.2.3.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33168.json"

Debian:12 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:6.*
2:6.1.7.3+dfsg-1
2:6.1.7.3+dfsg-2~deb12u1
2:6.1.7.3+dfsg-2
2:6.1.7.3+dfsg-3
2:6.1.7.3+dfsg-4
2:6.1.7.3+dfsg-5
2:6.1.7.3+dfsg-6
2:6.1.7.3+dfsg-7~exp1
2:6.1.7.3+dfsg-7
2:6.1.7.3+dfsg-8
2:6.1.7.3+dfsg-9
2:6.1.7.3+dfsg-10
2:6.1.7.3+dfsg-11
2:6.1.7.3+dfsg-12
2:6.1.7.3+dfsg-13
2:6.1.7.10+dfsg-1~deb12u1
2:6.1.7.10+dfsg-1~deb12u2
2:7.*
2:7.2.2.1+dfsg-1~exp1
2:7.2.2.1+dfsg-1~exp2
2:7.2.2.1+dfsg-1~exp3
2:7.2.2.1+dfsg-1~exp4
2:7.2.2.1+dfsg-1~exp6
2:7.2.2.1+dfsg-1
2:7.2.2.1+dfsg-2
2:7.2.2.1+dfsg-3
2:7.2.2.1+dfsg-4
2:7.2.2.1+dfsg-5
2:7.2.2.1+dfsg-6
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3
2:7.2.3.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33168.json"

Debian:13 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:7.*
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3
2:7.2.3.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33168.json"

Debian:14 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:7.2.3.1+dfsg-1

Affected versions

2:7.*
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33168.json"