Sploitus

CVE-2026-33168

No indexed exploits for CVE-2026-33168 yet

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Affected products
Rails, Red Os
Fix
Available
CVSS 4.0
2.3 LOW
EPSS
0.5% (41th percentile)
Weakness
CWE-79
NVD status
Deferred
Published
2026-03-23
CVE-2026-33168 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-33168 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-33168 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.