actionpack Security Analysis
actionpack has 20 known security vulnerabilities in RubyGems (Ruby). Upgrade to version 8.1.2.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Actively Exploited
CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.
Recommended safe version: 8.1.2.1
Upgrading to 8.1.2.1 or later resolves all 20 known vulnerabilities in actionpack. Run: gem install actionpack -v 8.1.2.1
Is actionpack in your project?
Check if you're affected and upgrade to 8.1.2.1 to stay secure.
Active Exploitation Warning
One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.
Vulnerabilities
20 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2016-0752 Directory traversal vulnerability in Action View in Ruby on Rails | HIGH | 4.0.0, 4.0.1, 4.0.1.rc1, 4.0.1.rc2 (+246 more) | 4.1.14.1, 4.2.5.1, 3.2.22.1 |
| CVE-2021-22904 Possible DoS Vulnerability in Action Controller Token Authentication | HIGH | 6.0.0, 6.0.1, 6.0.1.rc1, 6.0.2 (+190 more) | 6.0.3.7, 6.1.3.2, 5.2.6 (+1 more) |
| CVE-2021-22885 Action Pack contains Information Disclosure / Unintended Method Execution vulnerability | HIGH | 6.0.0, 6.0.1, 6.0.1.rc1, 6.0.2 (+339 more) | 6.0.3.7, 6.1.3.2, 5.2.6 (+1 more) |
| CVE-2016-0751 actionpack is vulnerable to denial of service via a crafted HTTP Accept header | HIGH | 4.2.0, 4.2.1, 4.2.1.rc1, 4.2.1.rc2 (+246 more) | 4.2.5.1, 3.2.22.1, 4.1.14.1 |
| CVE-2016-2098 actionpack allows remote code execution via application's unrestricted use of render method | HIGH | 3.0.0, 3.0.1, 3.0.10, 3.0.10.rc1 (+180 more) | 3.2.22.2, 4.1.14.2, 4.2.5.2 |
| CVE-2020-8164 Possible Strong Parameters Bypass in ActionPack | HIGH | 5.0.0, 5.0.0.1, 5.0.1, 5.0.1.rc1 (+61 more) | 5.2.4.3, 6.0.3.1 |
| CVE-2015-7581 actionpack is vulnerable to denial of service because of a wildcard controller route | HIGH | 4.0.0, 4.0.1, 4.0.1.rc1, 4.0.1.rc2 (+83 more) | 4.2.5.1 |
| CVE-2024-47887 Possible ReDoS vulnerability in HTTP Token authentication in Action Controller | MEDIUM | 4.0.0, 4.0.1, 4.0.1.rc1, 4.0.1.rc2 (+277 more) | 6.1.7.9, 7.0.8.5, 7.1.4.1 (+1 more) |
| CVE-2024-41128 Possible ReDoS vulnerability in query parameter filtering in Action Dispatch | MEDIUM | 3.1.0, 3.1.1, 3.1.1.rc1, 3.1.1.rc2 (+347 more) | 6.1.7.9, 7.0.8.5, 7.1.4.1 (+1 more) |
| CVE-2024-26143 Rails has possible XSS Vulnerability in Action Controller | MEDIUM | 7.0.0, 7.0.1, 7.0.2, 7.0.2.1 (+20 more) | 7.0.8.1, 7.1.3.1 |
| CVE-2024-28103 Missing security headers in Action Pack on non-HTML responses | MEDIUM | 6.1.0, 6.1.1, 6.1.2, 6.1.2.1 (+54 more) | 6.1.7.8, 7.0.8.4, 7.1.3.4 (+1 more) |
| CVE-2022-22577 Cross-site Scripting Vulnerability in Action Pack | MEDIUM | 5.2.0, 5.2.1, 5.2.1.1, 5.2.1.rc1 (+66 more) | 5.2.7.1, 6.0.4.8, 6.1.5.1 (+1 more) |
| CVE-2023-22797 Open Redirect Vulnerability in Action Pack | MEDIUM | 7.0.0, 7.0.1, 7.0.2, 7.0.2.1 (+6 more) | 7.0.4.1 |
| CVE-2020-8185 Untrusted users can run pending migrations in production in Rails | MEDIUM | 6.0.0, 6.0.1, 6.0.1.rc1, 6.0.2 (+7 more) | 6.0.3.2 |
| CVE-2021-44528 actionpack Open Redirect in Host Authorization Middleware | MEDIUM | 6.0.0, 6.0.1, 6.0.1.rc1, 6.0.2 (+24 more) | 6.0.4.2, 6.1.4.2 |
| CVE-2011-1497 Cross site scripting in actionpack Rubygem | MEDIUM | 3.0.0, 3.0.0.rc, 3.0.0.rc2, 3.0.1 (+8 more) | 3.0.6 |
| CVE-2021-22903 Possible Open Redirect Vulnerability in Action Pack | MEDIUM | 6.1.0, 6.1.0.rc2, 6.1.1, 6.1.2 (+3 more) | 6.1.3.2 |
| CVE-2016-2097 actionview contains Path Traversal vulnerability | MEDIUM | 3.0.0, 3.0.1, 3.0.10, 3.0.10.rc1 (+165 more) | 3.2.22.2, 4.1.14.2 |
| CVE-2026-33167 Rails has a possible XSS vulnerability in its Action Pack debug exceptions | LOW | 8.1.0, 8.1.1, 8.1.2 | 8.1.2.1 |
| CVE-2024-54133 Possible Content Security Policy bypass in Action Dispatch | LOW | 5.2.0, 5.2.1, 5.2.1.1, 5.2.1.rc1 (+138 more) | 7.0.8.7, 7.1.5.1, 7.2.2.1 (+1 more) |
About This Data
Vulnerability data for actionpack is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related RubyGems (Ruby) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of actionpack.