📦 Rack

by Rack

🔍 What is Rack?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-22860

HIGH CVSS 7.5 Feb 18, 2026

This vulnerability in Rack's Rack::Directory component allows attackers to bypass directory restrictions using path traversal techniques. By crafting requests like '/../root_example/', attackers can l...

CVE-2025-61772

HIGH CVSS 7.5 Oct 7, 2025

This vulnerability in Rack's multipart parser allows remote attackers to cause denial of service by sending incomplete multipart headers that trigger unbounded memory accumulation. All Ruby web applic...

CVE-2025-61770

HIGH CVSS 7.5 Oct 7, 2025

This vulnerability in Rack (Ruby web server interface) allows remote attackers to cause denial of service through memory exhaustion. By sending multipart/form-data requests with excessively large prea...

CVE-2025-46727

HIGH CVSS 7.5 May 7, 2025

This vulnerability in Rack's query parser allows attackers to send HTTP requests with extremely large numbers of parameters, causing memory exhaustion and CPU resource consumption. This leads to denia...

CVE-2025-27610

HIGH CVSS 7.5 Mar 10, 2025

This vulnerability in Rack's static file serving component allows attackers to bypass directory restrictions and access any file under the configured root directory using encoded path traversal sequen...

CVE-2025-27111

HIGH CVSS 7.5 Mar 4, 2025

CVE-2025-27111 is a log injection vulnerability in Rack's Sendfile middleware that allows attackers to inject escape sequences (like newlines) via the X-Sendfile-Type header. This can corrupt log file...

CVE-2023-27530

HIGH CVSS 7.5 Mar 10, 2023

This CVE describes a denial-of-service vulnerability in Rack's multipart MIME parsing code. Attackers can craft malicious requests that cause excessive processing time during multipart parsing, potent...

CVE-2022-44571

HIGH CVSS 7.5 Feb 9, 2023

CVE-2022-44571 is a denial of service vulnerability in Rack's Content-Disposition header parser that allows attackers to craft malicious inputs causing excessive processing time. This affects virtuall...

CVE-2026-25500

MEDIUM CVSS 5.4 Feb 18, 2026

This vulnerability allows cross-site scripting (XSS) attacks in Rack's directory listing feature. When Rack::Directory generates HTML directory indexes, it doesn't properly sanitize filenames starting...

CVE-2025-61780

MEDIUM CVSS 5.8 Oct 10, 2025

This vulnerability allows attackers to bypass proxy-level access restrictions in Rack applications using Rack::Sendfile with certain proxy configurations. By sending crafted x-sendfile-type and x-acce...

CVE-2023-27539

MEDIUM CVSS 5.3 Jan 9, 2025

CVE-2023-27539 is a denial-of-service vulnerability in Rack's header parsing component that allows attackers to cause excessive memory consumption by sending specially crafted HTTP headers. This affec...

CVE-2024-39316

MEDIUM CVSS 6.5 Jul 2, 2024

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in Rack's HTTP Accept header parsing. Attackers can send specially crafted Accept-Encoding or Accept-Language headers to...