CVEs we hold for Rack
Records whose assigning authority named Rack as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-39324Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationrack-session
CVE-2026-34835Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass.rack
CVE-2026-34830Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginxrack
CVE-2026-34829Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Lengthrack
CVE-2026-34230Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding headerrack
CVE-2026-25500Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor hrefrack
CVE-2025-61919Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingrack
CVE-2025-61772Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)rack
CVE-2025-61771Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)rack
CVE-2025-59830Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parametersrack
CVE-2024-35231rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameterrack-contrib
39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.