Search CVE reports


Toggle filters

1 – 10 of 59 results


CVE-2026-39324

Medium priority
Needs evaluation

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation...

2 affected packages

ruby-rack-session, ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-session Not in release Not in release
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34835

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34827

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition:...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-32762

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-26962

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34831

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34830

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34829

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34826

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of individual byte ranges. Although the existing fix...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34786

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, while the underlying file-serving...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages