Technology · RubyGems
rack (RubyGems) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in rack (RubyGems): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-34835, was published on 2 April 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About rack (RubyGems)
A modular interface for developing web applications in Ruby.
Latest rack (RubyGems) vulnerabilities
- CVE-2026-34835: Rack Rack::Request host allowlist bypass via Host header poisoningmediumCVSS 4.8EPSS 0.3%
- CVE-2026-34827: Rack algorithmic complexity denial of service in Multipart ParserhighCVSS 7.5EPSS 0.7%
- CVE-2026-32762: Rack interpretation conflict in Forwarded header parsingmediumCVSS 4.8EPSS 0.3%
- CVE-2026-26962: Rack CRLF injection in Rack::Multipart::ParsermediumCVSS 4.8EPSS 0.3%
- CVE-2026-34831: Rack incorrect Content-Length calculation in Rack::Files error responsesmediumCVSS 4.8EPSS 0.3%
- CVE-2026-34830: Rack Rack regular expression injection in Rack::SendfilemediumCVSS 5.9EPSS 0.4%
- CVE-2026-34829: Rack uncontrolled resource consumption in Rack::Multipart::ParserhighCVSS 7.5EPSS 0.7%
- CVE-2026-34826: Rack denial of service via excessive overlapping HTTP byte rangesmediumCVSS 5.3EPSS 0.5%
- CVE-2026-34786: Rack Rack::Static security header bypass via URL-encoded pathsmediumCVSS 5.3EPSS 0.3%
- CVE-2026-34785: Rack Rack::Static information disclosure via partial string matchinghighCVSS 7.5EPSS 0.5%
- CVE-2026-34763: Rack Rack::Directory information disclosure via unescaped regex interpolationmediumCVSS 5.3EPSS 0.3%
- CVE-2026-34230: Rack inefficient algorithmic complexity in Rack::Utils.select_best_encodinghighCVSS 7.5EPSS 0.5%
- CVE-2026-26961: Rack interpretation conflict in Multipart Parser boundary extractionmediumCVSS 5.3EPSS 0.3%
- CVE-2026-22860: Rack directory traversal in Rack::DirectoryhighCVSS 7.5EPSS 0.7%
- CVE-2025-59830: Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameterslowCVSS 3.1EPSS 0.6%
- CVE-2025-49007: ReDoS Vulnerability in Rack::Multipart handle_mime_headmediumCVSS 4EPSS 0.6%
- CVE-2025-32441: Rack session gets restored after deletionlowCVSS 3.1EPSS 0.2%
- CVE-2024-39316: Rack ReDoS Vulnerability in HTTP Accept Headers ParsinglowCVSS 3.1EPSS 0.9%
- CVE-2020-8161: Directory traversal in Rack::Directory app bundled with RacklowCVSS 3.1EPSS 3.4%
- CVE-2018-16470: Rack vulnerable to Denial of ServicelowCVSS 3EPSS 2.0%
Most severe rack (RubyGems) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-22860: Rack directory traversal in Rack::DirectoryhighCVSS 7.5EPSS 0.7%
- CVE-2026-34827: Rack algorithmic complexity denial of service in Multipart ParserhighCVSS 7.5EPSS 0.7%
- CVE-2026-34829: Rack uncontrolled resource consumption in Rack::Multipart::ParserhighCVSS 7.5EPSS 0.7%
- CVE-2026-34785: Rack Rack::Static information disclosure via partial string matchinghighCVSS 7.5EPSS 0.5%
- CVE-2026-34230: Rack inefficient algorithmic complexity in Rack::Utils.select_best_encodinghighCVSS 7.5EPSS 0.5%
- CVE-2026-34830: Rack Rack regular expression injection in Rack::SendfilemediumCVSS 5.9EPSS 0.4%
- CVE-2026-34826: Rack denial of service via excessive overlapping HTTP byte rangesmediumCVSS 5.3EPSS 0.5%
- CVE-2026-34786: Rack Rack::Static security header bypass via URL-encoded pathsmediumCVSS 5.3EPSS 0.3%
- CVE-2026-34763: Rack Rack::Directory information disclosure via unescaped regex interpolationmediumCVSS 5.3EPSS 0.3%
- CVE-2026-26961: Rack interpretation conflict in Multipart Parser boundary extractionmediumCVSS 5.3EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/rack.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "rack (RubyGems) vulnerabilities", https://junglewise.ai/threats/technologies/rack, 26 September 2026.