Description
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a `SafeBuffer` is mutated in place (e.g. via `gsub!`) and then formatted with `%` using untrusted arguments, the result incorrectly reports `html_safe? == true`, bypassing ERB auto-escaping and possibly leading to XSS. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
INFO
Published Date :
2026-03-23T23:09:48.923Z
Last Modified :
2026-03-25T19:20:28.280Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-33170 vulnerability.
| Vendors | Products |
|---|---|
| Rails |
|
| Rubyonrails |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-33170.