Loading...
Skip to main content

CVE-2026-34785

HIGH

Rack::Static prefix matching can expose unintended files under the static root

Published April 2, 2026Updated May 13, 2026Source: osv

Summary

## Summary `Rack::Static` determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as `"/css"`, it matches any request path that begins with that string, including unrelated paths such as `"/css-config.env"` or `"/css-backup.sql"`. As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. ## Details `Rack::Static#route_file` performs static-route matching using logic equivalent to: ```ruby @urls.any? { |url| path.index(url) == 0 } ``` This checks only whether the request path starts with the configured prefix string. It does not require a path segment boundary after the prefix. For example, with: ```ruby use Rack::Static, urls: ["/css", "/js"], root: "public" ``` the following path is matched as intended: ```text /css/style.css ``` but these paths are also matched: ```text /css-config.env /css-backup.sql /csssecrets.yml ``` If such files exist under the configured static root, Rack forwards the request to the file server and serves them as static content. This means a configuration intended to expose only directory trees such as `/css/...` and `/js/...` may also expose sibling files whose names begin with those same strings. ## Impact An attacker can request files under the configured static root whose names share a configured URL prefix and obtain their contents. In affected deployments, this may expose configuration files, secrets, backups, environment files, or other unintended static content located under the same root directory. ## Mitigation * Update to a patched version of Rack that enforces a path boundary when matching configured static URL prefixes. * Match only paths that are either exactly equal to the configured prefix or begin with `prefix + "/"`. * Avoid placing sensitive files under the `Rack::Static` root directory. * Prefer static URL mappings that cannot overlap with sensitive filenames.

Remediation

Upgrade to the fixed version using your package manager.

Bundler
Update rack to 2.2.23 or later
gem install rack -v 2.2.23
Bundler
Update rack to 3.2.6 or later
gem install rack -v 3.2.6
Bundler
Update rack to 3.1.21 or later
gem install rack -v 3.1.21

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (3)

PackageEcosystemAffectedFixed In
rack
rubygems
0.1.0, 0.2.0, 0.3.0, 0.4.0 (+119 more)2.2.23
rack
rubygems
3.2.0, 3.2.1, 3.2.2, 3.2.3 (+2 more)3.2.6
rack
rubygems
3.0.0, 3.0.0.beta1, 3.0.0.rc1, 3.0.1 (+42 more)3.1.21

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Frequently Asked Questions

What is CVE-2026-34785?
Rack::Static prefix matching can expose unintended files under the static root This vulnerability has been assigned a severity rating of HIGH (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2026-34785?
CVE-2026-34785 affects rack. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-34785 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-h2jq-g4cq-5ppq

Related CVEs

  • CVE-2026-34230
    HIGH

    Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

  • CVE-2026-34827
    HIGH

    Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters

  • CVE-2026-34831
    MEDIUM

    Rack has Content-Length mismatch in Rack::Files error responses

  • CVE-2026-34786
    MEDIUM

    Rack:: Static header_rules bypass via URL-encoded paths

  • CVE-2026-32762
    MEDIUM

    Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing

  • CVE-2026-34830
    MEDIUM

    Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect

  • CVE-2025-61780
    MEDIUM

    Rack has a Possible Information Disclosure Vulnerability

  • CVE-2026-26962
    MEDIUM

    Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies