{"api_version":"v1","generated_at":"2026-10-08T19:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-rails-activesupport-753aa0a2887a","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ActiveSupport","next_cursor":null,"observations":[{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33176","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33176","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T18:42:48.858Z","patch_url":"https://github.com/rails/rails/commit/19dbab51ca086a657bb86458042bc44314916bcb","primary_source":"","published":"2026-03-23T23:29:27.933Z"},{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33170","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33170","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-25T19:20:28.280Z","patch_url":"https://github.com/rails/rails/commit/50d732af3b7c8aaf63cbcca0becbc00279b215b7","primary_source":"","published":"2026-03-23T23:09:48.923Z"},{"affected":">= 8.1.0.beta1, < 8.1.2.1; >= 8.0.0.beta1, < 8.0.4.1; < 7.2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33169","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33169","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T15:46:43.465Z","patch_url":"https://github.com/rails/rails/commit/29154f1097da13d48fdb3200760b3e3da66dcb11","primary_source":"","published":"2026-03-23T23:07:07.630Z"},{"affected":">= 5.2.0 < >= 5.2.0","affected_versions_present":true,"cve_id":"CVE-2023-38037","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-38037","fixed":"5.2.0 < 5.2.0; 7.0.7.1, 6.1.7.5 < 7.0.7.1, 6.1.7.5","last_modified":"2025-02-15T00:10:27.790Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2023-38037-possible-file-disclosure-of-locally-encrypted-files/83544","primary_source":"","published":"2025-01-09T00:33:47.704Z"},{"affected":"7.0.4.3 < 7.0.4.3; 6.1.7.3 < 6.1.7.3","affected_versions_present":true,"cve_id":"CVE-2023-28120","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28120","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-01-09T21:46:38.220Z","patch_url":"","primary_source":"","published":"2025-01-09T00:33:47.658Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Rails"}}
