CVE-2024-26142

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/02/2024
Last modified:
14/02/2025

Description

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.3.1 (excluding)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 3.2.0 (excluding)