Technology · RubyGems
actionpack (RubyGems) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in actionpack (RubyGems): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-33167, was published on 23 March 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About actionpack (RubyGems)
A Ruby on Rails component for handling web requests and responses, including routing and controller logic.
Latest actionpack (RubyGems) vulnerabilities
- CVE-2026-33167: Rails has a possible XSS vulnerability in its Action Pack debug exceptionsmediumCVSS 4EPSS 0.3%
- CVE-2024-26142: Rails has possible ReDoS vulnerability in Accept header parsing in Action DispatchinfoEPSS 1.5%
- CVE-2023-22797: Open Redirect Vulnerability in Action PacklowCVSS 3.1EPSS 0.6%
- CVE-2022-3704: Cross-site Scripting in actionpacklowCVSS 3.1EPSS 0.7%
- CVE-2011-1497: Cross site scripting in actionpack RubygemlowCVSS 3.1EPSS 1.3%
- CVE-2021-22903: Possible Open Redirect Vulnerability in Action PacklowCVSS 3.1EPSS 1.2%
- CVE-2020-8264: Cross-site scripting in actionpacklowCVSS 3.1EPSS 67.0%
- CVE-2020-8185: Untrusted users can run pending migrations in production in RailslowCVSS 3.1EPSS 2.2%
- CVE-2011-0449: actionpack allows remote attackers to bypass intended access restrictionsinfoEPSS 2.5%
- CVE-2011-2929: actionpack Improper Input Validation vulnerabilityinfoEPSS 1.8%
- CVE-2011-3186: actionpack CRLF injection vulnerabilityinfoEPSS 1.8%
- CVE-2011-3187: actionpack Improper Input Validation vulnerabilityinfoEPSS 6.7%
- CVE-2015-7581: actionpack is vulnerable to denial of service because of a wildcard controller routelowCVSS 3EPSS 6.7%
- CVE-2013-6416: actionpack Cross-site Scripting vulnerabilityinfoEPSS 2.0%
- CVE-2014-0082: actionpack Improper Input Validation vulnerabilityinfoEPSS 6.2%
Most severe actionpack (RubyGems) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33167: Rails has a possible XSS vulnerability in its Action Pack debug exceptionsmediumCVSS 4EPSS 0.3%
- CVE-2020-8264: Cross-site scripting in actionpacklowCVSS 3.1EPSS 67.0%
- CVE-2020-8185: Untrusted users can run pending migrations in production in RailslowCVSS 3.1EPSS 2.2%
- CVE-2011-1497: Cross site scripting in actionpack RubygemlowCVSS 3.1EPSS 1.3%
- CVE-2021-22903: Possible Open Redirect Vulnerability in Action PacklowCVSS 3.1EPSS 1.2%
- CVE-2022-3704: Cross-site Scripting in actionpacklowCVSS 3.1EPSS 0.7%
- CVE-2023-22797: Open Redirect Vulnerability in Action PacklowCVSS 3.1EPSS 0.6%
- CVE-2015-7581: actionpack is vulnerable to denial of service because of a wildcard controller routelowCVSS 3EPSS 6.7%
- CVE-2011-3187: actionpack Improper Input Validation vulnerabilityinfoEPSS 6.7%
- CVE-2014-0082: actionpack Improper Input Validation vulnerabilityinfoEPSS 6.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/actionpack.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "actionpack (RubyGems) vulnerabilities", https://junglewise.ai/threats/technologies/actionpack, 27 September 2026.