Junglewise Threat Intelligence

CVE-2026-32762: Rack interpretation conflict in Forwarded header parsing

CVE-2026-32762 · Severity: medium · CVSS 4.8 · Published 2026-04-02

Technologies: Rack.

Executive brief

Rack is a standard interface used by Ruby web applications to communicate with web servers. A flaw in how it handles network headers allows attackers to manipulate information about the original request, such as the website's address or security protocol. This can lead to security issues like unauthorized redirects, incorrect logging, or the generation of malicious password reset links.

Technical details

The vulnerability exists in Rack::Utils.forwarded_values, which incorrectly parses RFC 7239 Forwarded headers by splitting on semicolons before processing quoted-string values. Because semicolons are legally permitted within quoted strings, an attacker can craft a header that Rack interprets as multiple directives (e.g., host, proto) while an upstream proxy or WAF sees it as a single value. This interpretation conflict allows for header smuggling. Attackers can exploit this to spoof request metadata such as req.host and req.scheme, which may impact security-sensitive operations like absolute URL generation or IP-based access control. The issue is patched in versions 3.1.21 and 3.2.6.

Affected products

  • Rack Rack >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6

Timeline

  • 2026-04-01: advisory: GitHub advisory GHSA-qfgr-crr9-7r49 published
  • 2026-04-02: disclosed: CVE-2026-32762 published

References