-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 04 Oct 2026 16:13:12 -0500 Source: rails Architecture: source Version: 2:7.2.2.2+dfsg-2~deb13u2 Distribution: trixie-security Urgency: high Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Simon Quigley <tsimonq2@debian.org> Closes: 1132035 1143080 Changes: rails (2:7.2.2.2+dfsg-2~deb13u2) trixie-security; urgency=high . * CVE-2026-66066: disable libvips unfuzzed loaders and savers when Active Storage loads ruby-vips. BMP, ICO, and PSD variants then raise Vips::Error (Closes: #1143080). * CVE-2026-33168: skip blank HTML attribute names in tag helpers. A blank attribute name bypasses escaping and produces malformed HTML. A crafted value can be read as a separate attribute, possibly leading to XSS (Closes: #1132035). * CVE-2026-33169: delimit numbers without the backtracking expression. The lookahead regular expression and gsub! can take quadratic time on a long digit string (Closes: #1132035). * CVE-2026-33170: keep an unsafe SafeBuffer unsafe after %. SafeBuffer#% does not copy the html_safe flag. Formatting a buffer mutated in place, with untrusted arguments, reports html_safe? and bypasses ERB escaping (Closes: #1132035). * CVE-2026-33173: drop analyzed, identified, and composed from direct uploads. Direct upload metadata can set those flags, skip MIME detection, and claim a safe content_type for other content (Closes: #1132035). * CVE-2026-33174: reject Active Storage byte ranges larger than 100MB. The proxy loads the whole requested byte range into memory. A large or unbounded Range header can exhaust memory. Ranges whose total size reaches 100MB are now rejected (Closes: #1132035). * CVE-2026-33176: do not expand scientific notation in number helpers. Strings such as 1e10000 are expanded by BigDecimal into a huge representation, which can exhaust memory and CPU (Closes: #1132035). * CVE-2026-33195: reject disk keys that leave the Active Storage root. DiskService#path_for does not keep the resolved path inside the storage root. A key containing ../ can read, write, or delete files outside it (Closes: #1132035). * CVE-2026-33202: escape glob metacharacters in DiskService#delete_prefixed. The prefix is passed to Dir.glob without escaping. A key containing glob metacharacters can delete a different file (Closes: #1132035). * CVE-2026-33658: allow only one byte range on Active Storage proxies. The proxy does not limit how many ranges a Range header may contain. Thousands of small ranges use much more CPU than one request for the same file (Closes: #1132035). Checksums-Sha1: 647af4aab1c6a55b60b9cb720554baa4e9c944c5 4704 rails_7.2.2.2+dfsg-2~deb13u2.dsc e1ce8744c85847eaf81dffb1c2436271dc3c43ec 115212 rails_7.2.2.2+dfsg-2~deb13u2.debian.tar.xz 01c194615a2b4599d171f1c019a63dc39f1148db 21120 rails_7.2.2.2+dfsg-2~deb13u2_source.buildinfo Checksums-Sha256: 2a17eb5a9c943ebf358525e1d170a1b93f685f7e657f5ad539871b513789b6c3 4704 rails_7.2.2.2+dfsg-2~deb13u2.dsc 33bf3623384401509bfc0a48ea864bdea8eae245a053cdf2789b37dd67688ab6 115212 rails_7.2.2.2+dfsg-2~deb13u2.debian.tar.xz b7d493a01e645b18147a6e8194b12d85e7b67e731a22b170870e04389344e1d2 21120 rails_7.2.2.2+dfsg-2~deb13u2_source.buildinfo Files: 26717cee511e673179ec708f9bf360bc 4704 ruby optional rails_7.2.2.2+dfsg-2~deb13u2.dsc 0507b6a8774496ada3dd0c1e29e0fc88 115212 ruby optional rails_7.2.2.2+dfsg-2~deb13u2.debian.tar.xz 70c96df2535b35d71d39989eaf15bb85 21120 ruby optional rails_7.2.2.2+dfsg-2~deb13u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmrD7SQACgkQ4n8s+EWM L6RDqA/9HhKKHzM9HRRtGTQM49Lk5WJZaCH/dGWZLnd4zbWAdyKVoanGvtIzg3P+ 8j1Ax2kvLiH44n0fsJkZIwxhT0+98AvxvP7PBa3CgITvrCva/DMAoQ1E5yDGtL6p 4uWtjsIwhkS55vmrePgTUpnR2cEVLxQnLFTHoMKjJvbYZ+g5W2vzRn0L0xnFeDvm eVf4fyc/Ukx3bQgl8j++D1NUg0/UFqlUQZUcxQhtv0uRqXGN3tdQ6DSrK/bSJBLP aUlaSAeLMxnJTqxuZQkYqyC5knVH16NHBF0E3glcyB2mbIO2TiSttDvlv9XF2MAP gUPWqlmI8N1TaW/O9+b4Nlw6iluQsEajRmSx4iJlKn3l8luv08H8wkQEdwI/gayD 5JGMPQ1vdt61JQ6IreI6jHyF5pAyrlQ7srxxsa7pnIDw2OtlNuKSZuWgfvl+dZn4 6vba5u+bIj3OLxFnkbE3Pkh0kRbXf6GQtB/z1/vfKRSHBCBTUHAn/VkehOPOlfG+ la9uSt7HnnNULi6SdHFWwr5xibxYS3McMed3mI/6jGFpTldVlTL5/F7ZZlVU12ta CmBod/bpfYcjSxeJl5458nyGD1kyW6DHIdrZjGlU3NZIpZzTgy+IEB6bvAZuTGW1 g91oPvGtJ9SDPQ+/dAfSqYtqT9A/DnT2EyNhUTTh2RKKW8RxqFs= =CF6D -----END PGP SIGNATURE-----