CVE-2026-33168
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
- Fix
- Available
- CVSS 4.0
- 2.3 LOW
- EPSS
- 0.5% (41th percentile)
- Weakness
- CWE-79
- NVD status
- Deferred
- Published
- 2026-03-23
No indexed exploits for CVE-2026-33168 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-33168 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.