CVE-2026-26962CRLF Injection in Rack

CWE-93CRLF Injection72 documents8 sources
Severity
4.8MEDIUMNVD
EPSS
0.1%
top 84.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 2
Latest updateApr 17

Description

Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack preserves the embedded CRLF in parsed parameter values such as filename or name instead of removing the folded line break during unfolding. As a result, applications that later reuse those parsed values in HTTP response headers may be vulnerable to downstream header injection

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5

Affected Packages2 packages

RubyGemsrack/rack3.2.03.2.6
CVEListV5rack/rack>= 3.2.0, < 3.2.6

🔴Vulnerability Details

5
OSV
CVE-2026-26962: (Rack is a modular Ruby web server interface2026-04-03
OSV
CVE-2026-26962: Rack is a modular Ruby web server interface2026-04-02
CVEList
Rack: Header injection in multipart requests2026-04-02
OSV
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values2026-04-02
GHSA
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values2026-04-02

📋Vendor Advisories

3
Ubuntu
Rack vulnerabilities2026-04-17
Red Hat
rack: Rack: Header injection and response splitting via incorrect multipart header parsing2026-04-02
Debian
CVE-2026-26962: ruby-rack - Rack is a modular Ruby web server interface. From version 3.2.0 to before versio...2026

🕵️Threat Intelligence

63
Wiz
CVE-2026-33635 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-25765 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-33210 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-34763 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-33168 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-26962 — CRLF Injection in Rack | cvebase