Výsledky hledání

CVE: CVE-2026-66066 výrobce: Ruby on Rails v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

1 karet z 2 položek

1

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our…

EPSS 0.02 CVSS 9.5 CVE-2026-66066 Ruby on Rails US

Rapid7 ·