Activesupport is a modestly deployed Ruby on Rails utility library that provides common extensions and support functionality across a wide range of web applications and services. Its observed vulnerability landscape centers on the Activesupport product itself and reflects recurring weaknesses in command injection, regular expression complexity, and resource consumption patterns typical of utility libraries that parse or process user-supplied input. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activesupport Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3779CRITICAL active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulne | Aug 10, 2018 | 9.8 | 33 | NO | NO |
CVE-2023-22796HIGH A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression en | Feb 9, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activesupport Project.
Media articles that mention a CVE ID that affects a product developed by Activesupport Project — matched by CVE ID, not by vendor name.