CVE-2015-7581: Rubyonrails Rails
High severity, CVSS 7.5. EPSS: 6.7% chance of exploitation in the next 30 days.
actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.
Affected products
- Rubyonrails Rails: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …
Published 2016-02-16. Last modified 2026-06-17.