Executive brief
Rack is a widely used interface for Ruby web applications that handles communication between web servers and application code. A flaw in how it processes web forms allows attackers to bypass security filters like Web Application Firewalls (WAFs). By sending specially crafted requests, an attacker can hide malicious data from security scanners while ensuring the application still processes it, potentially leading to unauthorized data modification or security policy bypass.
Technical details
A parser differential vulnerability exists in Rack's multipart/form-data handler due to the use of a greedy regular expression in Rack::Multipart::Parser. When a Content-Type header contains multiple boundary parameters, Rack selects the last occurrence, whereas many upstream proxies and Web Application Firewalls (WAFs) select the first. This interpretation conflict (CWE-436) allows an attacker to 'smuggle' multipart content past security intermediaries by having the intermediary inspect a 'safe' boundary while Rack processes a 'malicious' one. The issue is patched in versions 2.2.23, 3.1.21, and 3.2.6. Exploitation requires a layered architecture where an upstream component performs inspection based on the first boundary parameter.
Affected products
- Rack Rack < 2.2.23, >= 3.0.0.beta1 < 3.1.21, >= 3.2.0 < 3.2.6
Timeline
- 2026-04-01: advisory: GitHub Security Advisory published
- 2026-04-02: disclosed: CVE-2026-26961 published to NVD
- 2026-04-02: patched: Patched versions released