rack Security Analysis
rack has 34 known security vulnerabilities in RubyGems (Ruby). Upgrade to version 3.2.6 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 3.2.6
Upgrading to 3.2.6 or later resolves all 34 known vulnerabilities in rack. Run: gem install rack -v 3.2.6
Is rack in your project?
Check if you're affected and upgrade to 3.2.6 to stay secure.
Vulnerabilities
34 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2022-30123 Possible shell escape sequence injection vulnerability in Rack | CRITICAL | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+86 more) | 2.0.9.1, 2.1.4.1, 2.2.3.1 |
| CVE-2026-34829 Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-34230 Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-34785 Rack::Static prefix matching can expose unintended files under the static root | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-22860 Rack has a Directory Traversal via Rack:Directory | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+168 more) | 2.2.22, 3.1.20, 3.2.5 |
| CVE-2025-61919 Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+160 more) | 2.2.20, 3.1.18, 3.2.3 |
| CVE-2025-61772 Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion) | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+134 more) | 2.2.19, 3.1.17, 3.2.2 |
| CVE-2025-61771 Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion) | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+134 more) | 2.2.19, 3.1.17, 3.2.2 |
| CVE-2025-61770 Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+134 more) | 2.2.19, 3.1.17, 3.2.2 |
| CVE-2026-34827 Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters | HIGH | 3.0.0, 3.0.0.beta1, 3.0.0.rc1, 3.0.1 (+48 more) | 3.1.21, 3.2.6 |
| CVE-2025-46727 Rack has an Unbounded-Parameter DoS in Rack::QueryParser | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+144 more) | 2.2.14, 3.0.16, 3.1.14 |
| CVE-2025-59830 Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+114 more) | 2.2.18 |
| CVE-2023-27530 Rack has possible DoS Vulnerability in Multipart MIME parsing | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+102 more) | 2.0.9.3, 2.1.4.3, 2.2.6.3 (+1 more) |
| CVE-2022-44570 Denial of service via header parsing in Rack | HIGH | 1.5.0, 1.5.1, 1.5.2, 1.5.3 (+50 more) | 2.0.9.2, 2.1.4.2, 2.2.6.2 (+1 more) |
| CVE-2020-8161 Directory traversal in Rack::Directory app bundled with Rack | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+83 more) | 2.1.3 |
| CVE-2022-30122 Denial of Service Vulnerability in Rack Multipart Parsing | HIGH | 1.2.0, 1.2.1, 1.2.2, 1.2.3 (+70 more) | 2.0.9.1, 2.1.4.1, 2.2.3.1 |
| CVE-2020-8184 Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names | HIGH | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+87 more) | 2.1.4, 2.2.3 |
| CVE-2025-49007 ReDoS Vulnerability in Rack::Multipart handle_mime_head | MEDIUM | 3.1.0, 3.1.1, 3.1.10, 3.1.11 (+12 more) | 3.1.16 |
| CVE-2025-25184 Possible Log Injection in Rack::CommonLogger | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+133 more) | 2.2.11, 3.0.12, 3.1.10 |
| CVE-2026-34830 Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2025-61780 Rack has a Possible Information Disclosure Vulnerability | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+160 more) | 2.2.20, 3.1.18, 3.2.3 |
| CVE-2024-39316 Rack ReDoS Vulnerability in HTTP Accept Headers Parsing | MEDIUM | 3.1.0, 3.1.1, 3.1.2, 3.1.3 (+1 more) | 3.1.5 |
| CVE-2026-25500 Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+168 more) | 2.2.22, 3.1.20, 3.2.5 |
| CVE-2026-34763 Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-26961 Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass. | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-34826 Rack's multipart byte range processing allows denial of service via excessive overlapping ranges | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-34786 Rack:: Static header_rules bypass via URL-encoded paths | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2025-27111 Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+136 more) | 2.2.12, 3.0.13, 3.1.11 |
| CVE-2026-34831 Rack has Content-Length mismatch in Rack::Files error responses | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+171 more) | 2.2.23, 3.1.21, 3.2.6 |
| CVE-2026-34835 Rack::Request accepts invalid Host characters, enabling host allowlist bypass | MEDIUM | 3.0.0, 3.0.0.beta1, 3.0.0.rc1, 3.0.1 (+48 more) | 3.1.21, 3.2.6 |
| CVE-2026-32762 Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing | MEDIUM | 3.0.0, 3.0.0.beta1, 3.0.0.rc1, 3.0.1 (+48 more) | 3.1.21, 3.2.6 |
| CVE-2026-26962 Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values | MEDIUM | 3.2.0, 3.2.1, 3.2.2, 3.2.3 (+2 more) | 3.2.6 |
| CVE-2024-25126 Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial) | MEDIUM | 3.0.0, 3.0.1, 3.0.2, 3.0.3 (+114 more) | 3.0.9.1, 2.2.8.1 |
| CVE-2019-16782 Possible Information Leak / Session Hijack Vulnerability in Rack | MEDIUM | 0.1.0, 0.2.0, 0.3.0, 0.4.0 (+71 more) | 1.6.12, 2.0.8 |
About This Data
Vulnerability data for rack is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related RubyGems (Ruby) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of rack.