
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33658 is a Denial of Service (DoS) vulnerability in the Active Storage component of Ruby on Rails, specifically in its proxy controller's handling of HTTP Range headers. The proxy controller does not limit the number of byte ranges in a single request, allowing an authenticated attacker to send requests with thousands of small ranges that cause disproportionate CPU consumption. Affected versions include activestorage < 7.2.3.1, >= 8.0.0 and < 8.0.4.1, and >= 8.1.0 and < 8.1.2.1. The vulnerability was responsibly disclosed by HackerOne researcher thwin_htet and published on March 23, 2026. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 2.3 (Low) (GitHub Advisory, Ruby Advisory DB).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Active Storage's proxy controller processes HTTP Range header values without enforcing any cap on the number of byte ranges specified in a single request. An attacker can craft a request containing thousands of small, non-overlapping byte ranges targeting the same file; the server processes each range individually, resulting in CPU usage far exceeding that of a normal file request. The fix, attributed to Jean Boussier, limits range requests to a single range per request (GitHub Advisory, Rails v7.2.3.1 Release).
Successful exploitation degrades or denies service availability for legitimate users by exhausting server CPU resources. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. Any Rails application using Active Storage in proxy mode and accessible to authenticated (low-privilege) users is at risk, and sustained attacks could render the file-serving functionality or the broader application unresponsive (GitHub Advisory, Feedly).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires low-privilege (authenticated) access, reducing the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.045%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
config.active_storage.service_urls_expire_in is configured for proxy delivery) running an unpatched version (< 7.2.3.1, 8.0.x < 8.0.4.1, or 8.1.x < 8.1.2.1)./rails/active_storage/blobs/proxy/...).Range header containing thousands of small, distinct byte ranges, for example: Range: bytes=0-1, 2-3, 4-5, 6-7, ... (repeating for thousands of ranges)./rails/active_storage/blobs/proxy/) with abnormally large Range headers containing many comma-separated byte ranges from a single source IP.Range header values containing dozens or thousands of ranges; elevated response times or timeouts on these endpoints.ruby, puma, unicorn) without a corresponding spike in request volume; worker processes becoming unresponsive or timing out (GitHub Advisory).Upgrade to one of the patched versions of activestorage: 7.2.3.1, 8.0.4.1, or 8.1.2.1, which limit range requests to a single range per request. As a temporary workaround prior to patching, implement rate limiting on HTTP Range header requests at the reverse proxy or web server level (e.g., nginx, Apache), and consider blocking or restricting requests with Range headers containing multiple ranges. IBM Aspera Shares users should also apply the vendor-specific patch referenced in IBM's advisory (GitHub Advisory, Rails v8.1.2.1 Release, IBM Advisory).
The Rails core team published a coordinated security release on March 23, 2026, addressing CVE-2026-33658 alongside several other Active Storage vulnerabilities in the same patch batch. The official Rails blog announced versions 7.2.3.1, 8.0.4.1, and 8.1.2.1 simultaneously. IBM subsequently issued an advisory for IBM Aspera Shares, which bundles Rails, indicating downstream vendor impact. No significant independent researcher commentary or social media discussion beyond standard vulnerability tracking has been observed (Rails Blog, IBM Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."