11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether activestorage is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-66066
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
UNKNOWN
CVE-2026-33195
Rails Active Storage has possible Path Traversal in DiskService
UNKNOWN
CVE-2026-33174
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
UNKNOWN
CVE-2026-33173
Rails Active Storage has possible content type bypass via metadata in direct uploads
MEDIUM 6.5
CVE-2026-33658
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
UNKNOWN
CVE-2026-33202
Rails Active Storage has possible glob injection in its DiskService
MEDIUM 5.3
CVE-2024-26144
Rails has possible Sensitive Session Information Leak in Active Storage
CRITICAL 9.8
CVE-2022-21831
Possible code injection vulnerability in Rails / Active Storage
UNKNOWN
CVE-2025-24293
Active Storage allowed transformation methods that were potentially unsafe
HIGH 7.5
CVE-2020-8162
Circumvention of file size limits in ActiveStorage
MEDIUM 6.5
CVE-2018-16477
Exposure of Sensitive Information to an Unauthorized Actor in activestorage
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes