Debian Ruby-Rack vulnerabilities

50 known vulnerabilities affecting debian/ruby-rack.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM27LOW4

Vulnerabilities

Page 1 of 3
CVE-2026-34827HIGHCVSS 7.5fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34827 [HIGH] CVE-2026-34827: ruby-rack - Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before... Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using repeated String#index searches combined with String#slice! prefix deletion. For escape-heavy quoted values, this caus
debian
CVE-2026-34829HIGHCVSS 7.5fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34829 [HIGH] CVE-2026-34829: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is sent without a Content-Length header, such as with HTTP chunked transfer encoding, multipart parsing continues until end-of-stream with no
debian
CVE-2026-22860HIGHCVSS 7.5fixed in ruby-rack 2.2.22-0+deb12u1 (bookworm)2026
CVE-2026-22860 [HIGH] CVE-2026-22860: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and
debian
CVE-2026-34785HIGHCVSS 7.5fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34785 [HIGH] CVE-2026-34785: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "
debian
CVE-2026-25500MEDIUMCVSS 5.4fixed in ruby-rack 2.2.22-0+deb12u1 (bookworm)2026
CVE-2026-25500 [MEDIUM] CVE-2026-25500: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an HTML directory index where each file entry is rendered as a clickable link. If a file exists on disk whose basename starts with the `javascript:` scheme (e.g. `javascript:alert(1)`), the generated index contains an anchor whose `href` is exact
debian
CVE-2026-34786MEDIUMCVSS 5.3fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34786 [MEDIUM] CVE-2026-34786: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, while the underlying file-serving path is decoded before the file is served. As a result, a request for a URL-encoded variant of a static path can serve the same file w
debian
CVE-2026-34763MEDIUMCVSS 5.3fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34763 [MEDIUM] CVE-2026-34763: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex metacharacters such as +, *, or ., the prefix stripping can fail and the generated directory listing may expose the fu
debian
CVE-2026-34230MEDIUMCVSS 5.3fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34230 [MEDIUM] CVE-2026-34230: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding values with quadratic time complexity when the header contains many wildcard (*) entries. Because this method is used by Rack::Deflater to choose a response encoding, an unauthenticated attacker can send a single re
debian
CVE-2026-34830MEDIUMCVSS 5.9fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34830 [MEDIUM] CVE-2026-34830: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting file paths for X-Accel-Redirect. Because the header value is not escaped, an attacker who can supply X-Accel-Mapping to the backend c
debian
CVE-2026-26962MEDIUMCVSS 4.8fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-26962 [MEDIUM] CVE-2026-26962: ruby-rack - Rack is a modular Ruby web server interface. From version 3.2.0 to before versio... Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack preserves the embedded CRLF in parsed parameter values such as filename or name instead of removing the folded line break during unfolding.
debian
CVE-2026-32762MEDIUMCVSS 4.8fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-32762 [MEDIUM] CVE-2026-32762: ruby-rack - Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before... Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling quoted-string values. Because quoted values may legally contain semicolons, a header can be interpreted by Rack as multiple Forwarded direct
debian
CVE-2026-34831MEDIUMCVSS 4.8fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34831 [MEDIUM] CVE-2026-34831: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains multibyte UTF-8 characters, the declared Content-Length is smaller than the number of bytes actually sent on the wire. Because Rack::Files
debian
CVE-2026-34826MEDIUMCVSS 5.8fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34826 [MEDIUM] CVE-2026-34826: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of individual byte ranges. Although the existing fix for CVE-2024-26141 rejects ranges whose total byte coverage exceeds the file size, it does not restrict the count of ranges. An attacker
debian
CVE-2026-34835MEDIUMCVSS 4.8fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-34835 [MEDIUM] CVE-2026-34835: ruby-rack - Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before... Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts
debian
CVE-2026-26961LOWCVSS 3.7fixed in ruby-rack 3.2.6-2 (sid)2026
CVE-2026-26961 [LOW] CVE-2026-26961: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type header contains multiple boundary parameters, Rack selects the last one rather than the first. In deployments where an upstream proxy, WAF, o
debian
CVE-2025-46727HIGHCVSS 7.5fixed in ruby-rack 2.2.20-0+deb12u1 (bookworm)2025
CVE-2025-46727 [HIGH] CVE-2025-46727: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. The vulnerability arises
debian
CVE-2025-61919HIGHCVSS 7.5fixed in ruby-rack 2.2.20-0+deb12u1 (bookworm)2025
CVE-2025-61919 [HIGH] CVE-2025-61919: ruby-rack - Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, a... Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`, calling `rack.input.read(nil)` without enforcing a length or cap. Large request bodies can therefore be buffered completely into process memory before parsing
debian
CVE-2025-27610HIGHCVSS 7.5fixed in ruby-rack 2.2.13-1~deb12u1 (bookworm)2025
CVE-2025-27610 [HIGH] CVE-2025-27610: ruby-rack - Rack provides an interface for developing web applications in Ruby. Prior to ver... Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly. The vulnerability occurs because `Rack::Static` does not properly sanitize user-supplied pat
debian
CVE-2025-61770HIGHCVSS 7.5fixed in ruby-rack 2.2.20-0+deb12u1 (bookworm)2025
CVE-2025-61770 [HIGH] CVE-2025-61770: ruby-rack - Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17... Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the first boundary) in memory without any size limit. A client can send a large preamble followed by a valid boundary, causing significant memory use and potential process termination due to out-
debian
CVE-2025-61771HIGHCVSS 7.5fixed in ruby-rack 2.2.20-0+deb12u1 (bookworm)2025
CVE-2025-61771 [HIGH] CVE-2025-61771: ruby-rack - Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17... Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially le
debian
Debian Ruby-Rack vulnerabilities | cvebase