Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rack Session CRITICAL 9.8
CVE-2026-39324

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu…

Fix: 2.1.2+
Fix from $2,300 2026-04-07
Rack HIGH 7.5
CVE-2026-34827

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi…

Fix: 3.1.21 / 3.2.6+
Fix from $1,950 2026-04-02
Rack MEDIUM 6.5
CVE-2026-34835

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host hea…

Fix: 3.1.21 / 3.2.6+
Fix from $1,600 2026-04-02
Rack MEDIUM 6.5
CVE-2026-32762

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parse…

Fix: 3.1.21 / 3.2.6+
Fix from $1,600 2026-04-02
Rack MEDIUM 6.5
CVE-2026-26962

Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part header…

Fix: 3.2.6+
Fix from $1,600 2026-04-02
Rack HIGH 7.5
CVE-2026-34829

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34830

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack MEDIUM 6.5
CVE-2026-34831

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header us…

Fix: 2.2.23 / 3.1.21+
Fix from $1,600 2026-04-02
Rack HIGH 7.5
CVE-2026-34826

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack MEDIUM 5.3
CVE-2026-34786

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rule…

Fix: 2.2.23 / 3.1.21+
Fix from $1,600 2026-04-02
Rack HIGH 7.5
CVE-2026-34785

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served …

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack MEDIUM 5.3
CVE-2026-34763

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path direc…

Fix: 2.2.23 / 3.1.21+
Fix from $1,600 2026-04-02
Rack HIGH 7.5
CVE-2026-34230

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding …

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack MEDIUM 5.3
CVE-2026-26961

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter fro…

Fix: 2.2.23 / 3.1.21+
Fix from $1,600 2026-04-02
Rack MEDIUM 5.4
CVE-2026-25500

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an HTML directory index where e…

Fix: 2.2.22 / 3.1.20+
Fix from $1,600 2026-02-18
Rack HIGH 7.5
CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match o…

Fix: 2.2.22 / 3.1.20+
Fix from $1,950 2026-02-18
Rack HIGH 7.5
CVE-2025-61919

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into mem…

Fix: 2.2.20 / 3.1.18+
Fix from $1,950 2025-10-10
Rack MEDIUM 5.3
CVE-2025-61780

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in …

Fix: 2.2.20 / 3.1.18+
Fix from $1,600 2025-10-10
Rack HIGH 7.5
CVE-2025-61771

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (…

Fix: 2.2.19 / 3.1.17+
Fix from $1,950 2025-10-07
Rack HIGH 7.5
CVE-2025-61772

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data …

Fix: 2.2.19 / 3.1.17+
Fix from $1,950 2025-10-07
Rack HIGH 7.5
CVE-2025-61770

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart p…

Fix: 2.2.19 / 3.1.17+
Fix from $1,950 2025-10-07
Rack HIGH 7.5
CVE-2025-59830

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &,…

Fix: 2.2.18+
Fix from $1,950 2025-09-25
Rack MEDIUM 5.3
CVE-2025-49007

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the…

Fix: 3.1.16+
Fix from $1,600 2025-06-04
Rack HIGH 7.5
CVE-2025-46727

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/…

Fix: 2.2.14 / 3.0.16+
Fix from $1,950 2025-05-07
Rack HIGH 7.5
CVE-2025-27610

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files unde…

Fix: 2.2.13 / 3.0.14+
Fix from $1,950 2025-03-10
Rack HIGH 7.5
CVE-2025-27111

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacke…

Fix: 2.2.12 / 3.0.13+
Fix from $1,950 2025-03-04
Rack MEDIUM 6.5
CVE-2025-25184

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited…

Fix: 2.2.11 / 3.0.12+
Fix from $1,600 2025-02-12
Rack MEDIUM 5.3
CVE-2023-27539

There is a denial of service vulnerability in the header parsing component of Rack.

Fix: 2.2.6.4 / 3.0.6.1+
Fix from $1,600 2025-01-09
Rack MEDIUM 6.5
CVE-2024-39316

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulne…

Fix: 3.1.5+
Fix from $1,600 2024-07-02
Rack HIGH 7.5
CVE-2024-25126EPSS 35%

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expec…

Fix: 2.2.8.1 / 3.0.9.1+
Fix from $1,950 2024-02-29