Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Rack — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting Rack. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rack serves as a container orchestration platform, enabling developers to deploy and manage applications within isolated environments. Its architecture, which relies heavily on API interactions and web interfaces, has historically exposed it to a range of critical vulnerabilities. Among the 37 recorded CVEs, Remote Code Execution (RCE) and Cross-Site Scripting (XSS) represent the most prevalent threat vectors, often stemming from insufficient input validation in administrative endpoints. Additionally, privilege escalation flaws have allowed unauthorized users to gain elevated access, compromising the integrity of hosted workloads. While the platform offers robust isolation features, its complex dependency chain and frequent updates have occasionally introduced security gaps. These incidents highlight the necessity for rigorous patch management and strict access controls to mitigate risks associated with its containerized infrastructure.

Found 34 results / 37 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-26962 Rack: Header injection in multipart requests — rack CWE-93 4.8 Medium 2026-04-02
CVE-2026-34835 Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass. — rack CWE-1286 4.8 Medium 2026-04-02
CVE-2026-34827 Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser — rack CWE-407 7.5 High 2026-04-02
CVE-2026-32762 Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing — rack CWE-436 4.8 Medium 2026-04-02
CVE-2026-34830 Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx — rack CWE-625 5.9 Medium 2026-04-02
CVE-2026-34829 Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length — rack CWE-400 7.5 High 2026-04-02
CVE-2026-34826 Rack: Unbounded Range Count in get_byte_ranges Enables DoS — rack CWE-400 5.3 Medium 2026-04-02
CVE-2026-34786 Rack: Rack::Static header_rules bypass via URL-encoded paths — rack CWE-180 5.3 Medium 2026-04-02
CVE-2026-34785 Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching — rack CWE-187 7.5 High 2026-04-02
CVE-2026-34763 Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolation — rack CWE-625 5.3 Medium 2026-04-02
CVE-2026-34831 Rack: Content-Length mismatch in Rack::Files error responses — rack CWE-130 4.8 Medium 2026-04-02
CVE-2026-26961 Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypass — rack CWE-436 3.7 Low 2026-04-02
CVE-2026-34230 Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header — rack CWE-400 5.3 Medium 2026-04-02
CVE-2026-25500 Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href — rack CWE-79 5.4 Medium 2026-02-18
CVE-2026-22860 Rack has a Directory Traversal via Rack:Directory — rack CWE-22 7.5 High 2026-02-18
CVE-2025-61919 Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing — rack CWE-400 7.5 High 2025-10-10
CVE-2025-61780 Rack has Possible Information Disclosure Vulnerability — rack CWE-200 5.8 Medium 2025-10-10
CVE-2025-61772 Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion) — rack CWE-400 7.5 High 2025-10-07
CVE-2025-61771 Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion) — rack CWE-400 7.5 High 2025-10-07
CVE-2025-61770 Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) — rack CWE-400 7.5 High 2025-10-07
CVE-2025-59830 Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters — rack CWE-400 7.5 High 2025-09-25
CVE-2025-49007 ReDoS Vulnerability in Rack::Multipart handle_mime_head — rack CWE-770 7.5AI High AI 2025-06-04
CVE-2025-46727 Unbounded-Parameter DoS in Rack::QueryParser — rack CWE-400 7.5 High 2025-05-07
CVE-2025-32441 Rack session gets restored after deletion — rack CWE-362 4.2 Medium 2025-05-07
CVE-2025-27610 Local File Inclusion in Rack::Static — rack CWE-23 7.5 High 2025-03-10
CVE-2025-27111 Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection — rack CWE-93 5.3 - 2025-03-04
CVE-2025-25184 Possible Log Injection in Rack::CommonLogger — rack CWE-93 4.3 - 2025-02-12
CVE-2024-39316 Rack ReDoS Vulnerability in HTTP Accept Headers Parsing — rack CWE-1333 6.5 Medium 2024-07-02
CVE-2024-26141 Possible DoS Vulnerability with Range Header in Rack — rack CWE-400 5.8 Medium 2024-02-28
CVE-2024-25126 Rack ReDos in content type parsing (2nd degree polynomial) — rack CWE-1333 5.3 Medium 2024-02-28

This page lists every published CVE security advisory associated with Rack. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.