Skip to content

rails-5.2.2.gem: 136 vulnerabilities (highest severity is: 10.0) #20

Description

@mend-for-github-com
Vulnerable Library - rails-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/actionview-5.2.2.gem

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Vulnerabilities

Vulnerability Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (rails version) Remediation Possible** Reachability
CVE-2026-66066 Critical 10.0 Functional 27.861% activestorage-5.2.2.gem Transitive N/A*
CVE-2022-30123 Critical 10.0 Not Defined 1.801% rack-2.2.3.gem Transitive N/A*
CVE-2025-71407 Critical 9.8 Not Defined 0.418% nokogiri-1.10.9.gem Transitive N/A*
CVE-2025-24293 Critical 9.8 Functional 5.082% activestorage-5.2.2.gem Transitive N/A*
CVE-2024-58378 Critical 9.8 Not Defined 0.342% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-51000 Critical 9.8 Not Defined 0.441% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-32224 Critical 9.8 Not Defined 2.386% activerecord-5.2.2.gem Transitive N/A*
CVE-2022-21831 Critical 9.8 Not Defined 3.025% activestorage-5.2.2.gem Transitive N/A*
CVE-2020-8165 Critical 9.8 Not Defined 45.732% activesupport-5.2.2.gem Transitive N/A*
CVE-2019-5420 Critical 9.8 Functional 92.144% railties-5.2.2.gem Transitive N/A*
CVE-2026-33195 Critical 9.1 Not Defined 0.567% activestorage-5.2.2.gem Transitive N/A*
WS-2022-0089 High 8.8 Not Defined nokogiri-1.10.9.gem Transitive N/A*
CVE-2023-22794 High 8.8 Not Defined 2.153% activerecord-5.2.2.gem Transitive N/A*
CVE-2021-3518 High 8.8 Not Defined 3.653% nokogiri-1.10.9.gem Transitive N/A*
CVE-2021-30560 High 8.8 Not Defined 21.458% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-61666 High 8.6 Not Defined 0.338% websocket-driver-0.7.0.gem Transitive N/A*
CVE-2022-50999 High 8.6 Not Defined 0.301% nokogiri-1.10.9.gem Transitive N/A*
CVE-2021-3517 High 8.6 Not Defined 8.28% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-29181 High 8.2 Not Defined 3.23% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-23634 High 8.0 Not Defined 2.107% actionpack-5.2.2.gem Transitive N/A*
CVE-2025-71406 High 7.8 Not Defined 0.187% nokogiri-1.10.9.gem Transitive N/A*
WS-2023-0224 High 7.5 Not Defined actionpack-5.2.2.gem Transitive N/A*
CVE-2026-79770 High 7.5 Not Defined 0.278% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-54904 High 7.5 Not Defined 0.673% concurrent-ruby-1.1.4.gem Transitive N/A*
CVE-2026-34829 High 7.5 Not Defined 0.369% rack-2.2.3.gem Transitive N/A*
CVE-2026-34785 High 7.5 Not Defined 0.387% rack-2.2.3.gem Transitive N/A*
CVE-2026-33202 High 7.5 Not Defined 0.646% activestorage-5.2.2.gem Transitive N/A*
CVE-2026-33176 High 7.5 Not Defined 0.61% activesupport-5.2.2.gem Transitive N/A*
CVE-2026-33174 High 7.5 Not Defined 0.61% activestorage-5.2.2.gem Transitive N/A*
CVE-2026-22860 High 7.5 Not Defined 0.665% rack-2.2.3.gem Transitive N/A*
CVE-2025-61919 High 7.5 Not Defined 0.605% rack-2.2.3.gem Transitive N/A*
CVE-2025-61772 High 7.5 Not Defined 0.868% rack-2.2.3.gem Transitive N/A*
CVE-2025-61771 High 7.5 Not Defined 0.523% rack-2.2.3.gem Transitive N/A*
CVE-2025-61770 High 7.5 Not Defined 0.868% rack-2.2.3.gem Transitive N/A*
CVE-2025-59830 High 7.5 Not Defined 0.573% rack-2.2.3.gem Transitive N/A*
CVE-2025-46727 High 7.5 Not Defined 1.157% rack-2.2.3.gem Transitive N/A*
CVE-2025-27610 High 7.5 Not Defined 1.131% rack-2.2.3.gem Transitive N/A*
CVE-2024-47889 High 7.5 Not Defined 0.937% actionmailer-5.2.2.gem Transitive N/A*
CVE-2024-47887 High 7.5 Not Defined 1.041% actionpack-5.2.2.gem Transitive N/A*
CVE-2024-41128 High 7.5 Not Defined 1.095% actionpack-5.2.2.gem Transitive N/A*
CVE-2024-34459 High 7.5 Not Defined 2.298% nokogiri-1.10.9.gem Transitive N/A*
CVE-2023-54354 High 7.5 Not Defined 0.35% nokogiri-1.10.9.gem Transitive N/A*
CVE-2023-27530 High 7.5 Not Defined 1.83% rack-2.2.3.gem Transitive N/A*
CVE-2023-22799 High 7.5 Not Defined 1.049% globalid-0.4.2.gem Transitive N/A*
CVE-2023-22796 High 7.5 Not Defined 1.712% activesupport-5.2.2.gem Transitive N/A*
CVE-2023-22795 High 7.5 Not Defined 2.278% actionpack-5.2.2.gem Transitive N/A*
CVE-2023-22792 High 7.5 Not Defined 1.695% actionpack-5.2.2.gem Transitive N/A*
CVE-2022-50998 High 7.5 Not Defined 0.35% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-44572 High 7.5 Not Defined 1.617% rack-2.2.3.gem Transitive N/A*
CVE-2022-44571 High 7.5 Not Defined 1.503% rack-2.2.3.gem Transitive N/A*
CVE-2022-44570 High 7.5 Not Defined 1.626% rack-2.2.3.gem Transitive N/A*
CVE-2022-44566 High 7.5 Not Defined 1.265% activerecord-5.2.2.gem Transitive N/A*
CVE-2022-31163 High 7.5 Not Defined 2.23% tzinfo-1.2.5.gem Transitive N/A*
CVE-2022-30122 High 7.5 Not Defined 2.056% rack-2.2.3.gem Transitive N/A*
CVE-2022-24836 High 7.5 Not Defined 3.519% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-23517 High 7.5 Not Defined 1.454% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2022-23516 High 7.5 Not Defined 1.095% loofah-2.4.0.gem Transitive N/A*
CVE-2022-23514 High 7.5 Not Defined 1.686% loofah-2.4.0.gem Transitive N/A*
CVE-2021-47996 High 7.5 Not Defined 0.515% nokogiri-1.10.9.gem Transitive N/A*
CVE-2021-41098 High 7.5 Not Defined 1.447% nokogiri-1.10.9.gem Transitive N/A*
CVE-2021-22904 High 7.5 Not Defined 4.808% actionpack-5.2.2.gem Transitive N/A*
CVE-2021-22885 High 7.5 Not Defined 4.195% actionpack-5.2.2.gem Transitive N/A*
CVE-2021-22880 High 7.5 Not Defined 4.434% activerecord-5.2.2.gem Transitive N/A*
CVE-2020-8164 High 7.5 Not Defined 4.198% actionpack-5.2.2.gem Transitive N/A*
CVE-2020-8162 High 7.5 Not Defined 3.028% activestorage-5.2.2.gem Transitive N/A*
CVE-2019-5419 High 7.5 Not Defined 8.671% actionview-5.2.2.gem Transitive N/A*
CVE-2019-5418 High 7.5 High 98.507% actionview-5.2.2.gem Transitive N/A*
CVE-2018-25032 High 7.5 Not Defined 51.733% nokogiri-1.10.9.gem Transitive N/A*
CVE-2022-23633 High 7.4 Not Defined 2.226% actionpack-5.2.2.gem Transitive N/A*
CVE-2022-23519 High 7.2 Not Defined 0.988% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2026-57235 Medium 6.5 Not Defined 0.426% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-33658 Medium 6.5 Not Defined 0.434% activestorage-5.2.2.gem Transitive N/A*
CVE-2025-25184 Medium 6.5 Not Defined 1.162% rack-2.2.3.gem Transitive N/A*
CVE-2020-8167 Medium 6.5 Not Defined 1.485% actionview-5.2.2.gem Transitive N/A*
CVE-2023-23913 Medium 6.3 Not Defined 0.643% detected in multiple dependencies Transitive N/A*
CVE-2026-57438 Medium 6.2 Not Defined 0.125% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-73648 Medium 6.1 Not Defined 0.396% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2024-54133 Medium 6.1 Not Defined 1.009% actionpack-5.2.2.gem Transitive N/A*
CVE-2024-53989 Medium 6.1 Not Defined 0.463% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2024-53988 Medium 6.1 Not Defined 0.435% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2024-53987 Medium 6.1 Not Defined 0.435% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2024-53986 Medium 6.1 Not Defined 0.462% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2024-53985 Medium 6.1 Not Defined 0.581% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2022-32209 Medium 6.1 Not Defined 29.353% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2022-27777 Medium 6.1 Not Defined 1.639% actionview-5.2.2.gem Transitive N/A*
CVE-2022-23520 Medium 6.1 Not Defined 1.11% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2022-23518 Medium 6.1 Not Defined 0.867% rails-html-sanitizer-1.0.4.gem Transitive N/A*
CVE-2022-23515 Medium 6.1 Not Defined 0.792% loofah-2.4.0.gem Transitive N/A*
CVE-2022-22577 Medium 6.1 Not Defined 1.759% actionpack-5.2.2.gem Transitive N/A*
CVE-2026-34830 Medium 5.9 Not Defined 0.209% rack-2.2.3.gem Transitive N/A*
CVE-2021-3537 Medium 5.9 Not Defined 3.503% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-54465 Medium 5.8 Not Defined 0.344% websocket-driver-0.7.0.gem Transitive N/A*
CVE-2026-54464 Medium 5.8 Not Defined 0.445% websocket-driver-0.7.0.gem Transitive N/A*
CVE-2026-54463 Medium 5.8 Not Defined 0.344% websocket-driver-0.7.0.gem Transitive N/A*
CVE-2025-61780 Medium 5.8 Not Defined 0.434% rack-2.2.3.gem Transitive N/A*
CVE-2025-55193 Medium 5.8 Not Defined 0.565% activerecord-5.2.2.gem Transitive N/A*
CVE-2024-26141 Medium 5.8 Not Defined 1.612% rack-2.2.3.gem Transitive N/A*
CVE-2026-79769 Medium 5.5 Not Defined 0.181% nokogiri-1.10.9.gem Transitive N/A*
CVE-2024-58377 Medium 5.5 Not Defined 0.193% nokogiri-1.10.9.gem Transitive N/A*
CVE-2023-38037 Medium 5.5 Not Defined 0.274% activesupport-5.2.2.gem Transitive N/A*
CVE-2026-33168 Medium 5.4 Not Defined 0.713% actionview-5.2.2.gem Transitive N/A*
CVE-2026-25500 Medium 5.4 Not Defined 0.224% rack-2.2.3.gem Transitive N/A*
CVE-2020-15169 Medium 5.4 Not Defined 2.372% actionview-5.2.2.gem Transitive N/A*
CVE-2026-79772 Medium 5.3 Not Defined 0.262% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-79771 Medium 5.3 Not Defined 0.304% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-57437 Medium 5.3 Not Defined 0.402% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-57436 Medium 5.3 Not Defined 0.402% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-57435 Medium 5.3 Not Defined 0.46% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-57434 Medium 5.3 Not Defined 0.46% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-57236 Medium 5.3 Not Defined 0.341% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-54905 Medium 5.3 Not Defined 0.153% concurrent-ruby-1.1.4.gem Transitive N/A*
CVE-2026-34826 Medium 5.3 Not Defined 0.38% rack-2.2.3.gem Transitive N/A*
CVE-2026-34786 Medium 5.3 Not Defined 0.195% rack-2.2.3.gem Transitive N/A*
CVE-2026-34763 Medium 5.3 Not Defined 0.24% rack-2.2.3.gem Transitive N/A*
CVE-2026-34230 Medium 5.3 Not Defined 0.43% rack-2.2.3.gem Transitive N/A*
CVE-2026-33169 Medium 5.3 Not Defined 0.498% activesupport-5.2.2.gem Transitive N/A*
CVE-2025-27111 Medium 5.3 Not Defined 0.729% rack-2.2.3.gem Transitive N/A*
CVE-2024-26146 Medium 5.3 Not Defined 1.996% rack-2.2.3.gem Transitive N/A*
CVE-2024-26144 Medium 5.3 Not Defined 1.129% detected in multiple dependencies Transitive N/A*
CVE-2024-25126 Medium 5.3 Not Defined 35.376% rack-2.2.3.gem Transitive N/A*
CVE-2023-28120 Medium 5.3 Not Defined 0.923% activesupport-5.2.2.gem Transitive N/A*
CVE-2023-27539 Medium 5.3 Not Defined 1.081% rack-2.2.3.gem Transitive N/A*
CVE-2026-34831 Medium 4.8 Not Defined 0.147% rack-2.2.3.gem Transitive N/A*
CVE-2026-73490 Medium 4.7 Not Defined 0.18% loofah-2.4.0.gem Transitive N/A*
CVE-2026-33173 Medium 4.3 Not Defined 0.39% activestorage-5.2.2.gem Transitive N/A*
CVE-2026-33170 Medium 4.3 Not Defined 0.327% activesupport-5.2.2.gem Transitive N/A*
CVE-2020-8166 Medium 4.3 Not Defined 1.673% actionpack-5.2.2.gem Transitive N/A*
CVE-2025-32441 Medium 4.2 Not Defined 0.229% rack-2.2.3.gem Transitive N/A*
CVE-2026-54906 Medium 4.0 Not Defined 0.252% concurrent-ruby-1.1.4.gem Transitive N/A*
CVE-2023-28362 Medium 4.0 Not Defined 0.332% actionpack-5.2.2.gem Transitive N/A*
CVE-2020-5267 Medium 4.0 Not Defined 1.525% actionview-5.2.2.gem Transitive N/A*
CVE-2026-26961 Low 3.7 Not Defined 0.253% rack-2.2.3.gem Transitive N/A*
CVE-2025-6490 Low 3.3 Proof of concept 0.16% nokogiri-1.10.9.gem Transitive N/A*
CVE-2025-71346 Low 2.9 Not Defined 0.18% nokogiri-1.10.9.gem Transitive N/A*
CVE-2026-57234 Low 2.6 Not Defined 0.198% nokogiri-1.10.9.gem Transitive N/A*
CVE-2020-26247 Low 2.6 Not Defined 1.077% nokogiri-1.10.9.gem Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (10 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-66066

Vulnerable Library - activestorage-5.2.2.gem

Attach cloud and local files in Rails applications.

Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • activestorage-5.2.2.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Publish Date: 2026-07-30

URL: CVE-2026-66066

Threat Assessment

Exploit Maturity: Functional

EPSS: 27.861%

CVSS 3 Score Details (10.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-30

Fix Resolution: activestorage - 8.1.3.1,activestorage - 8.0.5.1,activestorage - 7.2.3.2,https://github.com/rails/rails.git - v8.0.5.1,https://github.com/rails/rails.git - v7.2.3.2,https://github.com/rails/rails.git - v8.1.3.1

CVE-2022-30123

Vulnerable Library - rack-2.2.3.gem

Rack provides a minimal, modular and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call.

Library home page: https://rubygems.org/gems/rack-2.2.3.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/rack-2.2.3.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • railties-5.2.2.gem
      • actionpack-5.2.2.gem
        • rack-2.2.3.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

Publish Date: 2022-12-05

URL: CVE-2022-30123

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 1.801%

CVSS 3 Score Details (10.0)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-wq4h-7r42-5hrr

Release Date: 2022-12-05

Fix Resolution: rack - 2.0.9.1,2.1.4.1,2.2.3.1

CVE-2025-71407

Vulnerable Library - nokogiri-1.10.9.gem

Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.

Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • railties-5.2.2.gem
      • actionpack-5.2.2.gem
        • rails-dom-testing-2.0.3.gem
          • nokogiri-1.10.9.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.

Publish Date: 2026-08-25

URL: CVE-2025-71407

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.418%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: nokogiri - 1.18.3,https://github.com/sparklemotion/nokogiri.git - v1.18.3

CVE-2025-24293

Vulnerable Library - activestorage-5.2.2.gem

Attach cloud and local files in Rails applications.

Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • activestorage-5.2.2.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: "<%= image_tag blob.variant(params[:t] => params[:v]) %>" Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong "ImageMagick security policy" (https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you "lio346" (https://hackerone.com/lio346) for reporting this!
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-01-30

URL: CVE-2025-24293

Threat Assessment

Exploit Maturity: Functional

EPSS: 5.082%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-r4mg-4433-c7g3

Release Date: 2026-01-30

Fix Resolution: https://github.com/rails/rails.git - v8.0.2.1,https://github.com/rails/rails.git - v7.2.2.2,https://github.com/rails/rails.git - v7.1.5.2

CVE-2024-58378

Vulnerable Library - nokogiri-1.10.9.gem

Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.

Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • railties-5.2.2.gem
      • actionpack-5.2.2.gem
        • rails-dom-testing-2.0.3.gem
          • nokogiri-1.10.9.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.

Publish Date: 2026-08-25

URL: CVE-2024-58378

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.342%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-xc9x-jj77-9p9j

Release Date: 2026-08-25

Fix Resolution: nokogiri - 1.15.6,nokogiri - 1.16.2,https://github.com/sparklemotion/nokogiri.git - v1.15.6,https://github.com/sparklemotion/nokogiri.git - v1.16.2

CVE-2022-51000

Vulnerable Library - nokogiri-1.10.9.gem

Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.

Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • railties-5.2.2.gem
      • actionpack-5.2.2.gem
        • rails-dom-testing-2.0.3.gem
          • nokogiri-1.10.9.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set to true and NOENT set to false may be vulnerable to denial of service, memory disclosure, or code execution. Nokogiri 1.13.2 upgrades vendored libxml2 to 2.9.13 and libxslt to 1.1.35.

Publish Date: 2026-08-25

URL: CVE-2022-51000

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.441%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: nokogiri - 1.13.2,https://github.com/sparklemotion/nokogiri.git - v1.13.2

CVE-2022-32224

Vulnerable Library - activerecord-5.2.2.gem

Databases on Rails. Build a persistent domain model by mapping database tables to Ruby classes. Strong conventions for associations, validations, aggregations, migrations, and testing come baked-in.

Library home page: https://rubygems.org/gems/activerecord-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activerecord-5.2.2.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • activerecord-5.2.2.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

Publish Date: 2022-12-05

URL: CVE-2022-32224

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.386%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-3hhc-qp5v-9p2j

Release Date: 2022-12-05

Fix Resolution: activerecord - 7.0.3.1,activerecord - 6.0.5.1,activerecord - 5.2.8.1,activerecord - 6.1.6.1

CVE-2022-21831

Vulnerable Library - activestorage-5.2.2.gem

Attach cloud and local files in Rails applications.

Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • activestorage-5.2.2.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

Publish Date: 2022-05-26

URL: CVE-2022-21831

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 3.025%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-w749-p3v6-hccq

Release Date: 2022-05-26

Fix Resolution: activestorage - 6.1.4.7,activestorage - 5.2.6.3,activestorage - 7.0.2.3,activestorage - 6.0.4.7

CVE-2020-8165

Vulnerable Library - activesupport-5.2.2.gem

A toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Rich support for multibyte strings, internationalization, time zones, and testing.

Library home page: https://rubygems.org/gems/activesupport-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activesupport-5.2.2.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • activesupport-5.2.2.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

Publish Date: 2020-06-19

URL: CVE-2020-8165

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 45.732%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-2p68-f74v-9wc6

Release Date: 2020-06-19

Fix Resolution: activesupport - 5.2.4.3,activesupport - 6.0.3.1

CVE-2019-5420

Vulnerable Library - railties-5.2.2.gem

Rails internals: application bootup, plugins, generators, and rake tasks.

Library home page: https://rubygems.org/gems/railties-5.2.2.gem

Sample Path to Dependency File: /Gemfile.lock

Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/railties-5.2.2.gem

Dependency Hierarchy:

  • rails-5.2.2.gem (Root Library)
    • railties-5.2.2.gem (Vulnerable Library)

Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7

Found in base branch: main

Vulnerability Details

A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.

Publish Date: 2019-03-27

URL: CVE-2019-5420

Threat Assessment

Exploit Maturity: Functional

EPSS: 92.144%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-m42h-mh85-4qgc

Release Date: 2019-03-27

Fix Resolution: railties - 5.2.2.1

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions