CRITICAL 9.6 CVE-2026-77087 Published 21 Aug 2026

Paperclip Local DNS Rebinding Vulnerability

Worried this affects one of your servers?

Paperclip, a Ruby gem for handling file uploads, is affected by a vulnerability that allows attackers to execute arbitrary commands via DNS rebinding.

In default local_trusted mode, Paperclip fails to validate Host headers, enabling an attacker to craft a malicious webpage. When a developer running Paperclip locally visits this page, DNS rebinding is used to make authenticated API requests and execute commands through the process adapter.

Reference: CVE-2026-77087 on NVD

← Back to Security News