Search CVE reports


Toggle filters

1 – 10 of 37 results


CVE-2025-49007

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-46727

Medium priority

Some fixes available 5 of 8

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Ignored
Show less packages

CVE-2025-46336

Medium priority
Needs evaluation

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-32441

Medium priority
Fixed

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-27610

Medium priority

Some fixes available 7 of 8

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-27111

Medium priority

Some fixes available 7 of 8

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-25184

Low priority

Some fixes available 7 of 8

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries....

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-39316

Medium priority
Ignored

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-35231

Medium priority
Needs evaluation

rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of service due to the fact that the user controlled data...

1 affected package

ruby-rack-contrib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-contrib Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-26146

Medium priority
Fixed

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Fixed
Show less packages