Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
💎
💎 RubyGems
Not in CISA KEV
HIGH severity

CVE-2022-23633 — actionpack

HIGHFix: rails/rails@f9a2ad0

CVE-2022-23633 is a high-severity (CVSS 7.4) Information Exposure vulnerability in actionpack. A fix is available for actionpack — see the affected versions and patch details below.

Exposure of sensitive information in Action Pack

Also known asGHSA-wh98-p28r-vrc9
Published
Updated
Affected
4 pkgs
Patched
4 / 4
Exploits
None indexed
Exploitation data as of Oct 7, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
2.2%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs82th percentile — riskier than 82% of all scored CVEsHighest risk
0.00%0.93%1.86%2.78%0.4%2.2%2.2%2.2%2.2%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2022-23633 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,738 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

4 pkgs affected
💎actionpack💎actionpack💎actionpack💎actionpack

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects RubyGems packages — download data is not available via public APIs for these ecosystems.

Description

Impact

Under certain circumstances response bodies will not be closed, for example a bug in a webserver or a bug in a Rack middleware. In the event a response is not notified of a close, ActionDispatch::Executor will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests, especially when interacting with ActiveSupport::CurrentAttributes.

Upgrading to the FIXED versions of Rails will ensure mitigation of this issue even in the context of a buggy webserver or middleware implementation.

Patches

This has been fixed in Rails 7.0.2.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2.

Workarounds

Upgrading is highly recommended, but to work around this problem the following middleware can be used:

class GuardedExecutor < ActionDispatch::Executor
  def call(env)
    ensure_completed!
    super
  end

  private

    def ensure_completed!
      @executor.new.complete! if @executor.active?
    end
end

# Ensure the guard is inserted before ActionDispatch::Executor
Rails.application.configure do
  config.middleware.swap ActionDispatch::Executor, GuardedExecutor, executor
end

Affected Packages

4 total 4 fixed
EcosystemPackageVulnerable rangeFix
💎RubyGemsactionpack≥ 5.0.0.0&&< 5.2.6.25.2.6.2bundle update actionpack --conservative
💎RubyGemsactionpack≥ 6.0.0.0&&< 6.0.4.66.0.4.6bundle update actionpack --conservative
💎RubyGemsactionpack≥ 6.1.0.0&&< 6.1.4.66.1.4.6bundle update actionpack --conservative
💎RubyGemsactionpack≥ 7.0.0.0&&< 7.0.2.27.0.2.2bundle update actionpack --conservative

Affected Products

2 products · 6 configurations
OS
debian linuxdebian
2 versions
10.011.0
Application
railsrubyonrails
≥ 7.0.0 && < 7.0.2.2
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for actionpack, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update actionpack to 5.2.6.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2022-23633 is resolved across your whole dependency graph.

  3. Workarounds

    Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatModerate
Workaround published by Red Hat
A workaround for this problem: ~~~ class GuardedExecutor < ActionDispatch::Executor def call(env) ensure_completed! super end private def ensure_completed! @executor.new.complete! if @executor.active? end end # Ensure the guard is inserted before ActionDispatch::Executor Rails.application.configure do config.middleware.swap ActionDispatch::Executor, GuardedExecutor, executor end ~~~
Source: Red Hat security advisory for CVE-2022-23633 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Satellite 6.11 for RHEL 7tfm-rubygem-actionpack-0:6.0.4.7-1.el7satRHSA-2022:5498

Frequently Asked Questions

### Impact Under certain circumstances response bodies will not be closed, for example a [bug in a webserver](https://github.com/puma/puma/pull/2812) or a bug in a Rack middleware. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests, especially when interacting with `ActiveSupport::CurrentAttributes`. Upgrading to the FIXED versions of Rails will ensure mitigation of this issue even in the context of a buggy webserver or middleware impleme
O3 Security · Impact-Aware SCA

Is CVE-2022-23633 in your dependencies?

Find it across RubyGems, including transitive dependencies.

CVE-2022-23633: actionpack — Fixed in 5.2.6.2