CVE Vulnerabilities

CVE-2024-26142

Inefficient Regular Expression Complexity

Published: Feb 27, 2024 | Modified: Jun 17, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
RailsRubyonrails7.1.0 (including)7.1.3.1 (excluding)
RailsUbuntubionic*
RailsUbuntuesm-apps/xenial*
RailsUbuntufocal*
RailsUbuntumantic*
RailsUbuntuoracular*
RailsUbuntuplucky*
RailsUbuntuquesting*
RailsUbuntutrusty*
RailsUbuntuxenial*
Rails-4.0Ubuntutrusty*
Ruby-actionpack-3.2Ubuntutrusty*
Ruby-activemodel-3.2Ubuntutrusty*
Ruby-activerecord-3.2Ubuntutrusty*
Ruby-activesupport-3.2Ubuntutrusty*
Ruby-rails-3.2Ubuntutrusty*

Potential Mitigations

References