CVE-2026-26962
- EPSS 0.02%
- Veröffentlicht 02.04.2026 17:10:17
- Zuletzt bearbeitet 21.04.2026 00:42:36
Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack preserves the embedded CRL...
CVE-2026-34835
- EPSS 0.15%
- Veröffentlicht 02.04.2026 17:09:07
- Zuletzt bearbeitet 03.04.2026 19:32:26
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant host...
CVE-2026-34827
- EPSS 0.02%
- Veröffentlicht 02.04.2026 17:07:48
- Zuletzt bearbeitet 24.04.2026 12:47:32
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using r...
CVE-2026-32762
- EPSS 0.05%
- Veröffentlicht 02.04.2026 17:06:50
- Zuletzt bearbeitet 21.04.2026 00:57:00
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling quoted-string values. Beca...
CVE-2026-34830
- EPSS 0.05%
- Veröffentlicht 02.04.2026 16:47:40
- Zuletzt bearbeitet 16.04.2026 16:50:50
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting file paths for X-Ac...
CVE-2026-34829
- EPSS 0.07%
- Veröffentlicht 02.04.2026 16:46:47
- Zuletzt bearbeitet 16.04.2026 16:54:00
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is sent without a Content-...
CVE-2026-34826
- EPSS 0.02%
- Veröffentlicht 02.04.2026 16:45:53
- Zuletzt bearbeitet 16.04.2026 17:09:16
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of individual byte ranges. Although the existing fix for CVE-2024-26141 rej...
CVE-2026-34786
- EPSS 0.04%
- Veröffentlicht 02.04.2026 16:44:59
- Zuletzt bearbeitet 16.04.2026 17:19:00
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, while the underlying file-serving path is decoded befo...
CVE-2026-34785
- EPSS 0.05%
- Veröffentlicht 02.04.2026 16:44:17
- Zuletzt bearbeitet 16.04.2026 17:19:35
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css"...
CVE-2026-34763
- EPSS 0.04%
- Veröffentlicht 02.04.2026 16:43:42
- Zuletzt bearbeitet 16.04.2026 17:26:24
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex meta...