CVE-2024-26144: Rubyonrails Rails
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
Affected products
- Rubyonrails Rails: from 5.2.0, before 6.1.7.7 (fixed in 6.1.7.7); from 7.0.0, before 7.1.0 (fixed in 7.1.0)
Published 2024-02-27. Last modified 2026-06-17.