{"api_version":"v1","generated_at":"2026-10-08T11:40:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-rails-activestorage-0992dfbe6a12","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/activestorage","name":"activestorage","next_cursor":null,"observations":[{"affected":">= 8.1.0, < 8.1.2.1; >= 8.0.0, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33658","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33658","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-30T11:42:24.885Z","patch_url":"","primary_source":"","published":"2026-03-26T21:03:25.319Z"},{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33202","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33202","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T15:44:19.018Z","patch_url":"https://github.com/rails/rails/commit/8c9676b803820110548cdb7523800db43bc6874c","primary_source":"","published":"2026-03-23T23:34:52.715Z"},{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33195","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33195","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-19T12:05:06.738Z","patch_url":"https://github.com/rails/rails/commit/4933c1e3b8c1bb04925d60347be9f69270392f2c","primary_source":"","published":"2026-03-23T23:31:41.785Z"},{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33174","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33174","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T13:40:32.031Z","patch_url":"https://github.com/rails/rails/commit/2cd933c366b777f873d4d590127da2f4a25e4ba5","primary_source":"","published":"2026-03-23T23:24:55.594Z"},{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33173","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33173","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T15:12:50.569Z","patch_url":"https://github.com/rails/rails/commit/707c0f1f41f067fdf96d54e99d43b28dfaae7e53","primary_source":"","published":"2026-03-23T23:21:29.843Z"},{"affected":"5.2 < 5.*; 7.0 < 7.1.5.2; 8.0 < 7.0.2.1","affected_versions_present":true,"cve_id":"CVE-2025-24293","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-24293","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:26:46.864Z","patch_url":"","primary_source":"","published":"2026-01-30T20:11:15.219Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"rails"}}
