Rack / Rack
50 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-26962 | Rack: Header injection in multipart requests | MEDIUM | 6.5 | Apr 2, 2026 |
| CVE-2026-34835 | Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass. | MEDIUM | 6.5 | Apr 2, 2026 |
| CVE-2026-34827 | Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-32762 | Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing | MEDIUM | 6.5 | Apr 2, 2026 |
| CVE-2026-34830 | Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-34829 | Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-34826 | Rack: Unbounded Range Count in get_byte_ranges Enables DoS | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-34786 | Rack: Rack::Static header_rules bypass via URL-encoded paths | MEDIUM | 6.5 | Apr 2, 2026 |
| CVE-2026-34785 | Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-34763 | Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolation | MEDIUM | 5.3 | Apr 2, 2026 |
| CVE-2026-34831 | Rack: Content-Length mismatch in Rack::Files error responses | MEDIUM | 6.5 | Apr 2, 2026 |
| CVE-2026-26961 | Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypass | MEDIUM | 5.3 | Apr 2, 2026 |
| CVE-2026-34230 | Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-25500 | Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href | MEDIUM | 5.4 | Feb 18, 2026 |
| CVE-2026-22860 | Rack has a Directory Traversal via Rack:Directory | HIGH | 7.5 | Feb 18, 2026 |
| CVE-2025-61919 | Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing | HIGH | 7.5 | Oct 10, 2025 |
| CVE-2025-61780 | Rack has Possible Information Disclosure Vulnerability | MEDIUM | 5.8 | Oct 10, 2025 |
| CVE-2025-61772 | Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion) | HIGH | 7.5 | Oct 7, 2025 |
| CVE-2025-61771 | Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion) | HIGH | 7.5 | Oct 7, 2025 |
| CVE-2025-61770 | Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) | HIGH | 7.5 | Oct 7, 2025 |
| CVE-2025-59830 | Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters | HIGH | 7.5 | Sep 25, 2025 |
| CVE-2025-49007 | ReDoS Vulnerability in Rack::Multipart handle_mime_head | MEDIUM | 6.6 | Jun 4, 2025 |
| CVE-2025-46727 | Unbounded-Parameter DoS in Rack::QueryParser | HIGH | 7.5 | May 7, 2025 |
| CVE-2025-32441 | Rack session gets restored after deletion | MEDIUM | 4.2 | May 7, 2025 |
| CVE-2025-27610 | Local File Inclusion in Rack::Static | HIGH | 7.5 | Mar 10, 2025 |
Showing 1 to 25 of 50 CVEs