vciy

CVEs we hold for Rack

Records whose assigning authority named Rack as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-39324Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationrack-session
CVE-2026-34835Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass.rack
CVE-2026-34831Rack: Content-Length mismatch in Rack::Files error responsesrack
CVE-2026-34830Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginxrack
CVE-2026-34829Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Lengthrack
CVE-2026-34827Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parserrack
CVE-2026-34826Rack: Unbounded Range Count in get_byte_ranges Enables DoSrack
CVE-2026-34786Rack: Rack::Static header_rules bypass via URL-encoded pathsrack
CVE-2026-34785Rack: Local file inclusion in `Rack::Static` via URL Prefix Matchingrack
CVE-2026-34763Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolationrack
CVE-2026-34230Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding headerrack
CVE-2026-32762Rack: Forwarded Header semicolon injection enables Host and Scheme spoofingrack
CVE-2026-26962Rack: Header injection in multipart requestsrack
CVE-2026-26961Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypassrack
CVE-2026-25500Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor hrefrack
CVE-2026-22860Rack has a Directory Traversal via Rack:Directoryrack
CVE-2026-18819RackTables cross-site request forgeryn/a RackTables
CVE-2025-61919Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingrack
CVE-2025-61780Rack has Possible Information Disclosure Vulnerabilityrack
CVE-2025-61772Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)rack
CVE-2025-61771Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)rack
CVE-2025-61770Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)rack
CVE-2025-59830Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parametersrack
CVE-2025-49007ReDoS Vulnerability in Rack::Multipart handle_mime_headrack
CVE-2025-46727Unbounded-Parameter DoS in Rack::QueryParserrack
CVE-2025-46336Rack session gets restored after deletionrack-session
CVE-2025-32441Rack session gets restored after deletionrack
CVE-2025-27610Local File Inclusion in Rack::Staticrack
CVE-2025-27111Escape Sequence Injection vulnerability in Rack lead to Possible Log Injectionrack
CVE-2025-25184Possible Log Injection in Rack::CommonLoggerrack
CVE-2024-39316Rack ReDoS Vulnerability in HTTP Accept Headers Parsingrack
CVE-2024-35231rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameterrack-contrib
CVE-2024-26146Possible Denial of Service Vulnerability in Rack Header Parsingrack
CVE-2024-26141Possible DoS Vulnerability with Range Header in Rackrack
CVE-2024-25126Rack ReDos in content type parsing (2nd degree polynomial)rack
CVE-2021-32773Confused deputy attack in sandbox module resolutionracket
CVE-2019-16782Possible Information Leak / Session Hijack Vulnerability in Rackrack
CVE-2018-16471no title heldRack
CVE-2018-16470no title heldRack

39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.