<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Ruby on Rails</title><description>Vulnerability disclosures, patches, and security advisories for Ruby on Rails and its ecosystem — including Active Storage, Action Pack, and other framework components. Rails powers a broad share of production web applications, so critical flaws in shared components can expose application secrets and server files across thousands of deployments simultaneously. Combined article + CVE feed for the Ruby on Rails beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2026-66066 — Ruby on Rails Active Storage arbitrary file read via libvips</title><link>https://0daynews.com/cve/cve-2026-66066/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-66066/</guid><description>Unauthenticated file read in Rails Active Storage via libvips image processing. CVSSv4 9.5, critical. Patch released July 29, 2026.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Ruby on Rails</category><category>critical</category><category>cve</category></item><item><title>Rails Patches Critical File Read via Image Upload</title><link>https://0daynews.com/articles/2026-07-29-rails-active-storage-critical-file-read/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-rails-active-storage-critical-file-read/</guid><description>Ruby on Rails patches a critical Active Storage flaw letting unauthenticated attackers read server files—exposing app secrets and database credentials through crafted image uploads.</description><pubDate>Wed, 29 Jul 2026 18:30:00 GMT</pubDate><category>Ruby on Rails</category><category>article</category></item></channel></rss>