CVE-2024-26142

    Dashboard / Vulnerabilities / CVE-2024-26142

    CVE-2024-26142

    Published: 27 Feb 2024Last Modified: 9 Sept 2026

    Summary: Rails possible ReDoS vulnerability in Accept header parsing in Action Dispatch

    Details: Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- d39db5d1891f7509cde2efc425c9d69bbb77e670

    Affected versions

    v7.1.3
    v7.1.2
    v7.1.1
    v7.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-26142 | CVE-DB