HackerOne Disclosed Reports - 2026-06-09

0 Replies, 3 Views

Logo
Low
resolved

Action Text ReDoS (Ruby 3.1 or lower)


Bug reported by ooooooo_q was disclosed at June 9, 2026, 4:37 am   |   Uncontrolled Resource Consumption

A vulnerability was discovered in the ActionText component of the Rails web framework for Ruby versions 3.1 and lower. The vulnerability was caused by a Regular Expression Denial of Service (ReDoS) issue in the plain_text_for_blockquote_node method. This method was used in the ActionText::Fragment#to_plain_text functionality. The vulnerability could be triggered by crafting malicious text and calling the to_plain_text method. The vulnerability was resolved in later versions of Ruby.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)