CVE-2026-33658: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-33658 is a Denial of Service (DoS) vulnerability in the Active Storage component of Ruby on Rails, specifically in its proxy controller's handling of HTTP Range headers. The proxy controller does not limit the number of byte ranges in a single request, allowing an authenticated attacker to send requests with thousands of small ranges that cause disproportionate CPU consumption. Affected versions include activestorage < 7.2.3.1, >= 8.0.0 and < 8.0.4.1, and >= 8.1.0 and < 8.1.2.1. The vulnerability was responsibly disclosed by HackerOne researcher thwin_htet and published on March 23, 2026. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 2.3 (Low) (GitHub Advisory, Ruby Advisory DB).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Active Storage's proxy controller processes HTTP Range header values without enforcing any cap on the number of byte ranges specified in a single request. An attacker can craft a request containing thousands of small, non-overlapping byte ranges targeting the same file; the server processes each range individually, resulting in CPU usage far exceeding that of a normal file request. The fix, attributed to Jean Boussier, limits range requests to a single range per request (GitHub Advisory, Rails v7.2.3.1 Release).

Impact

Successful exploitation degrades or denies service availability for legitimate users by exhausting server CPU resources. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. Any Rails application using Active Storage in proxy mode and accessible to authenticated (low-privilege) users is at risk, and sustained attacks could render the file-serving functionality or the broader application unresponsive (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires low-privilege (authenticated) access, reducing the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.045%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Identify target: Locate a Rails application using Active Storage in proxy mode (i.e., config.active_storage.service_urls_expire_in is configured for proxy delivery) running an unpatched version (< 7.2.3.1, 8.0.x < 8.0.4.1, or 8.1.x < 8.1.2.1).
  2. Authenticate: Obtain a valid low-privilege user account on the target application, as the attack requires authenticated access.
  3. Identify a proxied file URL: Find or upload a file accessible via Active Storage's proxy controller endpoint (e.g., /rails/active_storage/blobs/proxy/...).
  4. Craft malicious request: Construct an HTTP GET request to the proxied file URL with a Range header containing thousands of small, distinct byte ranges, for example: Range: bytes=0-1, 2-3, 4-5, 6-7, ... (repeating for thousands of ranges).
  5. Send repeated requests: Dispatch multiple such requests concurrently to amplify CPU exhaustion on the server, potentially causing degraded response times or a full denial of service for other users (GitHub Advisory).

Indicators of compromise

  • Network: Repeated HTTP GET requests to Active Storage proxy endpoints (e.g., /rails/active_storage/blobs/proxy/) with abnormally large Range headers containing many comma-separated byte ranges from a single source IP.
  • Logs: Rails application logs showing high-frequency requests to Active Storage proxy paths with Range header values containing dozens or thousands of ranges; elevated response times or timeouts on these endpoints.
  • Process: Sustained high CPU utilization on the Rails application server process (e.g., ruby, puma, unicorn) without a corresponding spike in request volume; worker processes becoming unresponsive or timing out (GitHub Advisory).

Mitigation and workarounds

Upgrade to one of the patched versions of activestorage: 7.2.3.1, 8.0.4.1, or 8.1.2.1, which limit range requests to a single range per request. As a temporary workaround prior to patching, implement rate limiting on HTTP Range header requests at the reverse proxy or web server level (e.g., nginx, Apache), and consider blocking or restricting requests with Range headers containing multiple ranges. IBM Aspera Shares users should also apply the vendor-specific patch referenced in IBM's advisory (GitHub Advisory, Rails v8.1.2.1 Release, IBM Advisory).

Community reactions

The Rails core team published a coordinated security release on March 23, 2026, addressing CVE-2026-33658 alongside several other Active Storage vulnerabilities in the same patch batch. The official Rails blog announced versions 7.2.3.1, 8.0.4.1, and 8.1.2.1 simultaneously. IBM subsequently issued an advisory for IBM Aspera Shares, which bundles Rails, indicating downstream vendor impact. No significant independent researcher commentary or social media discussion beyond standard vulnerability tracking has been observed (Rails Blog, IBM Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails

Affected

sid

rails: 2:7.2.3.1+dfsg-1

Fixed

trixie

rails

Affected

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management