ManageIQ / ManageIQ/httpd_configmap_generator
CVE-2026-33170 (Medium) detected in activesupport-7.2.2.2.gem
- Dominant language
- Ruby
- Stars
- 3
- Forks
- 16
- PR merge metrics
- No merged PRs in 30d
Description
## CVE-2026-33170 - Medium Severity Vulnerability
Vulnerable Library - activesupport-7.2.2.2.gem
A toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Rich support for multibyte strings, internationalization, time zones, and testing.
Library home page: https://rubygems.org/gems/activesupport-7.2.2.2.gem
Path to dependency file: /Gemfile.lock
Path to vulnerable library: /vendor/cache/activesupport-7.2.2.2.gem
Dependency Hierarchy:
- manageiq-style-1.5.9.gem (Root Library)
- rubocop-rails-2.29.1.gem
- :x: **activesupport-7.2.2.2.gem** (Vulnerable Library)
Found in base branch: master
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, "SafeBuffer#%" does not propagate the "@html_unsafe" flag to the newly created buffer. If a "SafeBuffer" is mutated in place (e.g. via "gsub!") and then formatted with "%" using untrusted arguments, the result incorrectly reports "html_safe? == true", bypassing ERB auto-escaping and possibly leading to XSS. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Publish Date: 2026-03-23
URL: CVE-2026-33170
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Type: Upgrade version
Release Date: 2026-03-23
Fix Resolution: https://github.com/rails/rails.git - v8.0.4.1,https://github.com/rails/rails.git - v7.2.3.1,https://github.com/rails/rails.git - v8.1.2.1,https://github.com/rails/rails.git - v8.1.3,https://github.com/rails/rails.git - v8.0.5
***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)
Contributor guide
Research direction
Start with /Gemfile.lock and the cached dependency at /vendor/cache/activesupport-7.2.2.2.gem, following the dependency path through rubocop-rails. Update Active Support to a listed fixed version and verify that the vulnerable version is no longer present in the dependency files.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ruby
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100