DEBIAN-CVE-2026-33658

Source
https://security-tracker.debian.org/tracker/CVE-2026-33658
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33658.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-33658
Upstream
Published
2026-03-26T22:16:29.387Z
Modified
2026-04-16T17:03:31.567167Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

References

Affected packages

Debian:11 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:6.*
2:6.0.3.7+dfsg-2
2:6.0.3.7+dfsg-2+deb11u1
2:6.0.3.7+dfsg-2+deb11u2
2:6.0.3.7+dfsg-2+deb11u3
2:6.0.3.7+dfsg-2+deb11u4
2:6.0.3.7+dfsg-3
2:6.1.4+dfsg-1
2:6.1.4+dfsg-2
2:6.1.4+dfsg-3
2:6.1.4+dfsg-4
2:6.1.4.1+dfsg-1
2:6.1.4.1+dfsg-2
2:6.1.4.1+dfsg-3
2:6.1.4.1+dfsg-4
2:6.1.4.1+dfsg-5
2:6.1.4.1+dfsg-6
2:6.1.4.1+dfsg-7
2:6.1.4.1+dfsg-8
2:6.1.4.6+dfsg-1
2:6.1.4.6+dfsg-2
2:6.1.4.6+dfsg-3
2:6.1.4.7+dfsg-1
2:6.1.4.7+dfsg-2
2:6.1.6.1+dfsg-1
2:6.1.6.1+dfsg-2
2:6.1.6.1+dfsg-3
2:6.1.6.1+dfsg-4
2:6.1.7+dfsg-1
2:6.1.7+dfsg-2
2:6.1.7+dfsg-3~bpo11+1
2:6.1.7+dfsg-3~bpo11+2
2:6.1.7+dfsg-3
2:6.1.7.3+dfsg-1~bpo11+1
2:6.1.7.3+dfsg-1
2:6.1.7.3+dfsg-2~deb12u1
2:6.1.7.3+dfsg-2
2:6.1.7.3+dfsg-3
2:6.1.7.3+dfsg-4
2:6.1.7.3+dfsg-5
2:6.1.7.3+dfsg-6
2:6.1.7.3+dfsg-7~exp1
2:6.1.7.3+dfsg-7
2:6.1.7.3+dfsg-8
2:6.1.7.3+dfsg-9
2:6.1.7.3+dfsg-10
2:6.1.7.3+dfsg-11
2:6.1.7.3+dfsg-12
2:6.1.7.3+dfsg-13
2:6.1.7.10+dfsg-1~deb12u1
2:6.1.7.10+dfsg-1~deb12u2
2:7.*
2:7.2.2.1+dfsg-1~exp1
2:7.2.2.1+dfsg-1~exp2
2:7.2.2.1+dfsg-1~exp3
2:7.2.2.1+dfsg-1~exp4
2:7.2.2.1+dfsg-1~exp6
2:7.2.2.1+dfsg-1
2:7.2.2.1+dfsg-2
2:7.2.2.1+dfsg-3
2:7.2.2.1+dfsg-4
2:7.2.2.1+dfsg-5
2:7.2.2.1+dfsg-6
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3
2:7.2.3.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33658.json"

Debian:12 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:6.*
2:6.1.7.3+dfsg-1
2:6.1.7.3+dfsg-2~deb12u1
2:6.1.7.3+dfsg-2
2:6.1.7.3+dfsg-3
2:6.1.7.3+dfsg-4
2:6.1.7.3+dfsg-5
2:6.1.7.3+dfsg-6
2:6.1.7.3+dfsg-7~exp1
2:6.1.7.3+dfsg-7
2:6.1.7.3+dfsg-8
2:6.1.7.3+dfsg-9
2:6.1.7.3+dfsg-10
2:6.1.7.3+dfsg-11
2:6.1.7.3+dfsg-12
2:6.1.7.3+dfsg-13
2:6.1.7.10+dfsg-1~deb12u1
2:6.1.7.10+dfsg-1~deb12u2
2:7.*
2:7.2.2.1+dfsg-1~exp1
2:7.2.2.1+dfsg-1~exp2
2:7.2.2.1+dfsg-1~exp3
2:7.2.2.1+dfsg-1~exp4
2:7.2.2.1+dfsg-1~exp6
2:7.2.2.1+dfsg-1
2:7.2.2.1+dfsg-2
2:7.2.2.1+dfsg-3
2:7.2.2.1+dfsg-4
2:7.2.2.1+dfsg-5
2:7.2.2.1+dfsg-6
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3
2:7.2.3.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33658.json"

Debian:13 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:7.*
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3
2:7.2.3.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33658.json"

Debian:14 / rails

Package

Name
rails
Purl
pkg:deb/debian/rails?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:7.2.3.1+dfsg-1

Affected versions

2:7.*
2:7.2.2.1+dfsg-7
2:7.2.2.2+dfsg-1
2:7.2.2.2+dfsg-2~deb13u1
2:7.2.2.2+dfsg-2
2:7.2.3+dfsg-1
2:7.2.3+dfsg-2
2:7.2.3+dfsg-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33658.json"