51 Total advisories
51 Vulnerabilities
0 Malware

Dependency scanning

Check whether rack is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.3
RubyGems

CVE-2026-34826

Rack's multipart byte range processing allows denial of service via excessive overlapping ranges

MEDIUM 5.3
RubyGems

CVE-2026-26961

Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.

MEDIUM 4.8
RubyGems

CVE-2026-26962

Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values

HIGH 7.5
RubyGems

CVE-2026-34230

Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

MEDIUM 5.9
RubyGems

CVE-2026-34830

Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect

MEDIUM 4.8
RubyGems

CVE-2026-32762

Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing

MEDIUM 5.3
RubyGems

CVE-2026-34786

Rack:: Static header_rules bypass via URL-encoded paths

MEDIUM 4.8
RubyGems

CVE-2026-34831

Rack has Content-Length mismatch in Rack::Files error responses

HIGH 7.5
RubyGems

CVE-2026-34785

Rack::Static prefix matching can expose unintended files under the static root

HIGH 7.5
RubyGems

CVE-2026-34829

Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads

MEDIUM 5.8
RubyGems

CVE-2025-61780

Rack has a Possible Information Disclosure Vulnerability

HIGH 7.5
RubyGems

CVE-2025-59830

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

HIGH 7.5
RubyGems

CVE-2025-46727

Rack has an Unbounded-Parameter DoS in Rack::QueryParser

HIGH 7.5
RubyGems

CVE-2026-34827

Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters

MEDIUM 4.8
RubyGems

CVE-2026-34835

Rack::Request accepts invalid Host characters, enabling host allowlist bypass

MEDIUM 5.3
RubyGems

CVE-2026-34763

Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory

MEDIUM 5.4
RubyGems

CVE-2026-25500

Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href

HIGH 7.5
RubyGems

CVE-2026-22860

Rack has a Directory Traversal via Rack:Directory

HIGH 7.5
RubyGems

CVE-2025-61771

Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)

HIGH 7.5
RubyGems

CVE-2025-61772

Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)

HIGH 7.5
RubyGems

CVE-2025-61770

Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

HIGH 7.5
RubyGems

CVE-2025-61919

Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing

UNKNOWN
RubyGems

CVE-2025-49007

ReDoS Vulnerability in Rack::Multipart handle_mime_head

MEDIUM 4.2
RubyGems

CVE-2025-32441

Rack session gets restored after deletion

UNKNOWN
RubyGems

CVE-2025-27111

Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection

MEDIUM 6.5
RubyGems

CVE-2025-25184

Possible Log Injection in Rack::CommonLogger

UNKNOWN
RubyGems

CVE-2024-26146

Rack Header Parsing leads to Possible Denial of Service Vulnerability

MEDIUM 5.3
RubyGems

CVE-2024-25126

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

UNKNOWN
RubyGems

CVE-2024-26141

Rack has possible DoS Vulnerability with Range Header

HIGH 7.5
RubyGems

CVE-2025-27610

Local File Inclusion in Rack::Static

HIGH 7.5
RubyGems

CVE-2020-8184

Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names

MEDIUM 6.3
RubyGems

CVE-2019-16782

Possible Information Leak / Session Hijack Vulnerability in Rack

HIGH 8.6
RubyGems

CVE-2020-8161

Directory traversal in Rack::Directory app bundled with Rack

MEDIUM 6.5
RubyGems

CVE-2024-39316

Rack ReDoS Vulnerability in HTTP Accept Headers Parsing

HIGH 7.5
RubyGems

CVE-2022-44570

Denial of service via header parsing in Rack

HIGH 7.5
RubyGems

CVE-2023-27530

Rack has possible DoS Vulnerability in Multipart MIME parsing

UNKNOWN
RubyGems

CVE-2023-27539

Possible Denial of Service Vulnerability in Rack's header parsing

UNKNOWN
RubyGems

CVE-2013-0184

Rack vulnerable to Denial of Service

UNKNOWN
RubyGems

CVE-2013-0263

Rack arbitrary code execution via timing attack

UNKNOWN
RubyGems

CVE-2013-0183

Rack rubygems receiving excessively long lines triggers out-of-memory error

UNKNOWN
RubyGems

CVE-2015-3225

Rack vulnerable to Denial of Service via large parameter depth request

UNKNOWN
RubyGems

GHSA-9vc2-p34x-jhxh

Moderate severity vulnerability that affects rack

UNKNOWN
RubyGems

CVE-2022-44572

Denial of service via multipart parsing in Rack

UNKNOWN
RubyGems

CVE-2022-44571

Denial of Service Vulnerability in Rack Content-Disposition parsing

UNKNOWN
RubyGems

CVE-2011-5036

Rack Gem Subject to Denial of Service via Hash Collisions

UNKNOWN
RubyGems

CVE-2012-6109

Rack vulnerable to REDoS

UNKNOWN
RubyGems

CVE-2013-0262

Rack Vulnerable to Path Traversal

CRITICAL 10.0
RubyGems

CVE-2022-30123

Possible shell escape sequence injection vulnerability in Rack

HIGH 7.5
RubyGems

CVE-2022-30122

Denial of Service Vulnerability in Rack Multipart Parsing

MEDIUM 6.1
RubyGems

CVE-2018-16471

Rack vulnerable to Cross-site Scripting

HIGH 7.5
RubyGems

CVE-2018-16470

Rack vulnerable to Denial of Service

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes