-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 04 Oct 2026 20:40:34 -0500 Source: rails Architecture: source Version: 2:6.1.7.10+dfsg-1~deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Simon Quigley <tsimonq2@debian.org> Closes: 1132035 1143080 Changes: rails (2:6.1.7.10+dfsg-1~deb12u3) bookworm-security; urgency=medium . * Team upload. * CVE-2026-66066: block libvips untrusted loaders when the variant processor is :vips. BMP, ICO, and PSD variants then raise Vips::Error. The MiniMagick default is unchanged (Closes: #1143080). * CVE-2026-33168: skip blank HTML attribute names in tag helpers. A blank attribute name bypasses escaping and produces malformed HTML. A crafted value can be read as a separate attribute, possibly leading to XSS (Closes: #1132035). * CVE-2026-33169: delimit numbers without the backtracking expression. The lookahead regular expression and gsub! can take quadratic time on a long digit string (Closes: #1132035). * CVE-2026-33170: keep an unsafe SafeBuffer unsafe after %. SafeBuffer#% does not copy the html_safe flag. Formatting a buffer mutated in place, with untrusted arguments, reports html_safe? and bypasses ERB escaping (Closes: #1132035). * CVE-2026-33173: drop analyzed and identified from direct uploads. Direct upload metadata can set those flags, skip MIME detection, and claim a safe content_type for other content (Closes: #1132035). * CVE-2026-33176: do not expand scientific notation in number helpers. Strings such as 1e10000 are expanded by BigDecimal into a huge representation, which can exhaust memory and CPU (Closes: #1132035). * CVE-2026-33195: reject disk keys that leave the Active Storage root. DiskService#path_for does not keep the resolved path inside the storage root. A key containing ../ can read, write, or delete files outside it (Closes: #1132035). * CVE-2026-33202: escape glob metacharacters in DiskService#delete_prefixed. The prefix is passed to Dir.glob without escaping. A key containing glob metacharacters can delete a different file (Closes: #1132035). Checksums-Sha1: bc26ca716ffcbafdd44b203b2f6bd87d623a4d2b 4847 rails_6.1.7.10+dfsg-1~deb12u3.dsc 524a4396a90673002ad430ff29cb329b2e4febc0 111344 rails_6.1.7.10+dfsg-1~deb12u3.debian.tar.xz a14349a2e678140825587af7fa55e502d876e40a 21016 rails_6.1.7.10+dfsg-1~deb12u3_source.buildinfo Checksums-Sha256: a4813a44fb0915d53961aaf21f4796ec49fbb79fbc430a49eea097a57aead1f3 4847 rails_6.1.7.10+dfsg-1~deb12u3.dsc f5ddad95b123fe3eaa94f498ded1c027649bf7ee5e27e169a9a43f53e042da47 111344 rails_6.1.7.10+dfsg-1~deb12u3.debian.tar.xz 13befed246ae3f080fdbb271f69bb9037de6ddee55931713e2d00356f7243145 21016 rails_6.1.7.10+dfsg-1~deb12u3_source.buildinfo Files: ec0c9e633b906209f484f61f9ec32316 4847 ruby optional rails_6.1.7.10+dfsg-1~deb12u3.dsc 785c1723da67a8d343f65a76540e01f8 111344 ruby optional rails_6.1.7.10+dfsg-1~deb12u3.debian.tar.xz d815dae95a03278d045267c7bec19698 21016 ruby optional rails_6.1.7.10+dfsg-1~deb12u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmrHvacACgkQ4n8s+EWM L6SYSRAApIVxY6XWXwloPvc5Z5p5OBeLCKL1zlegRnP0zxbrFf4B3C58V6NKI8u0 T+afxh4qa9J/EfidQNTBmaBo++/R1yoWOqz4PlqGfll7rh6THedJoMxi/qXS+xJ7 Ws0MyvkO0xW4PGgfC0XV96BN4Dxr2b9yMGUX2GINN+vlBmJRSp1QYmdbLyg3YjC1 M3/AGksCBQ00lca+8Ey7FxMtePisVwVgeiXOxYbJEk4GOAVWPdgX+zH8X7UFdQDj OKNZLicObV3NlIyERb5Yjp1nqPFP9e6lhzBIBgWZEKS830XDMslRTlCee5U2GkJ2 88aw8O1KCbY2eCNVhrIu7b6FvAaX9AmaEgl4PIWjiSouPzWbkdOTS266z5jH34O9 PAaY8V5n3JjceCilJbPjFAo4Ukx87mIw3jsPgNKHce1pPzNSstwd8fxGLKFzMkwy w61aezMIjRwoMhPrLZRD0HfoMdRz7peg9XKu4DV3M2uwPgD/s2BUbemjNpUMt6Ur WB1utvelRcXXB0KPel7RpZohVPmMzDUmHs1xIWMTmxi9YZtUk584vK0ARcgXMoKN wVCbSH8RZo251F4XERIFCBKTkRw60UWz2H9qVFIKIY7bn0jNpMdkV2nQWb/KDAL4 zhfaWTIg005VvW45wYTleQSMpB5e027br9vMgzzobhV3JTJ4MYc= =P6yG -----END PGP SIGNATURE-----