MEDIUM6.5
GHSA-p9fm-f462-ggrg
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Quick fix
GHSA-p9fm-f462-ggrg — activestorage: upgrade to the fixed version with the command below.
bundle update activestorageDetails
### Impact Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a normal request for the same file, possibly resulting in a DoS vulnerability.
### Releases The fixed releases are available at the normal locations.
### Credit This issue was responsibly reported by Hackerone researcher [thwin_htet](https://hackerone.com/thwin_htet).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rails/rails/security/advisories/GHSA-p9fm-f462-ggrg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-33658[ADVISORY]
- https://github.com/rails/rails[PACKAGE]
- https://github.com/rails/rails/releases/tag/v7.2.3.1[WEB]
- https://github.com/rails/rails/releases/tag/v8.0.4.1[WEB]
- https://github.com/rails/rails/releases/tag/v8.1.2.1[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-33658.yml[WEB]