CVE-2015-7581: Rubyonrails Rails

High severity, CVSS 7.5. EPSS: 6.7% chance of exploitation in the next 30 days.

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.

Affected products

  • Rubyonrails Rails: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …

Published 2016-02-16. Last modified 2026-06-17.