Executive brief
Rack is a standard interface used by many Ruby web applications to handle web requests. A vulnerability in how it handles 'Host' headers allows attackers to bypass security checks by including special characters that the system incorrectly accepts. This can lead to 'host header poisoning,' where an attacker tricks the application into generating malicious links, performing unauthorized redirects, or bypassing security filters intended to restrict access to trusted domains.
Technical details
The Rack::Request component uses an AUTHORITY regular expression that fails to strictly adhere to RFC 3986. It accepts non-compliant characters such as '/', '?', '#', and '@' in the Host header. Because req.host returns the full unvalidated string, applications performing naive validation (e.g., using .start_with? or .end_with?) can be bypassed by an attacker-controlled Host header like 'myapp.com@evil.com'. This enables host header poisoning, which can be leveraged for malicious link generation, open redirects, or origin validation bypass. The issue is fixed in Rack versions 3.1.21 and 3.2.6.
Affected products
- Rack Rack >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6
Timeline
- 2026-04-01: advisory: GitHub Security Advisory published
- 2026-04-02: disclosed: CVE-2026-34835 published to NVD