Visit Rails NES Home Page
Rails 5.2.x Release Notes
13 versions
Changelog and Release Notes for the NES version of Rails 5.2
April 2026
5.2.8.41
Released Apr 23, 2026Security Fixes
- CVE-2026-41316 - Fix for ERB vulnerability when using
Marshal.load.
Active Record
- CVE-2022-44566 – Resolve incomplete denial-of-service (DoS) fix from earlier release.
March 2026
5.2.8.39
Released Mar 24, 2026Security Fixes
Action View
- CVE-2026-33168 — Fix possible XSS vulnerability in tag helpers.
Active Storage
- CVE-2026-33658 - Fix possible DoS vulnerability in proxy mode via multi-range requests.
- CVE-2026-33202 — Fix possible glob injection in
DiskService. - CVE-2026-33195 — Fix possible path traversal in
DiskService. - CVE-2026-33174 - Fix possible DoS vulnerability in proxy mode via Range requests.
- CVE-2026-33173 — Fix insufficient filtering of metadata in direct uploads.
Active Support
- CVE-2026-33176 — Fix possible DoS vulnerability in number helpers.
- CVE-2026-33170 — Fix possible XSS vulnerability in
SafeBuffer#%. - CVE-2026-33169 — Fix possible ReDoS vulnerability in
number_to_delimited.
October 2025
5.2.8.37
Released Oct 30, 2025Notes
- No changes in Rails.
- Bumped Rack version requirement to version 2.2.20.11.
5.2.8.36
Released Oct 13, 2025Notes
- No changes in Rails.
- Bumped Rack version requirement to version 2.2.20.10.
August 2025
5.2.8.33
Released Aug 20, 2025Security Fixes
Active Record
- CVE-2025-55193 - Call inspect on ids in
RecordNotFounderror.
Active Storage
- CVE-2025-24293 - Remove dangerous transformations.
June 2025
May 2025
February 2025
5.2.8.26
Released Feb 10, 2025Notes
- This is the initial release of Never-Ending Support (NES) for Rails v5.2.x.
Security Fixes
Action Mailer
- CVE-2024-47889 – Avoid regex backtracking in
block_formathelper.
Action Pack
- CVE-2024-54133 – Fixed a possible Content Security Policy bypass in Action Dispatch.
- CVE-2024-47887 – Fixed a possible ReDoS vulnerability in HTTP Token authentication in Action Controller.
- CVE-2024-41128 – Fixed a possible ReDoS vulnerability in query parameter filtering in Action Dispatch.
- CVE-2023-28362 – Raise an exception if illegal characters are provide to
redirect_to. - CVE-2023-22795 – Fixed a ReDoS-based DoS vulnerability in Action Dispatch.
- CVE-2023-22792 – Fixed a ReDoS-based DoS vulnerability in Action Dispatch.
Action View
- CVE-2023-23913 – Fixed a DOM-based cross-site scripting (XSS) vulnerability in rails-ujs affecting contenteditable HTML elements.
Active Record
- CVE-2022-44566 – Fixed a denial-of-service (DoS) vulnerability in ActiveRecord's PostgreSQL adapter.
- CVE-2022-32224 – Fixed an Active Record RCE bug with serialized columns.
Active Support
- CVE-2023-38037 – Fixed a potential information disclosure vulnerability in Active Support where locally encrypted files could be exposed.
- CVE-2023-28120 – Fixed a possible XSS security vulnerability in
SafeBuffer#bytesplice. - CVE-2023-22796 – Fixed a ReDoS-based DoS vulnerability in Active Support's underscore.
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh