Dependency scanning
Check whether rack is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-34826
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
CVE-2026-26961
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
CVE-2026-26962
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
CVE-2026-34230
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVE-2026-34830
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
CVE-2026-32762
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
CVE-2026-34786
Rack:: Static header_rules bypass via URL-encoded paths
CVE-2026-34831
Rack has Content-Length mismatch in Rack::Files error responses
CVE-2026-34785
Rack::Static prefix matching can expose unintended files under the static root
CVE-2026-34829
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVE-2025-61780
Rack has a Possible Information Disclosure Vulnerability
CVE-2025-59830
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
CVE-2025-46727
Rack has an Unbounded-Parameter DoS in Rack::QueryParser
CVE-2026-34827
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
CVE-2026-34835
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
CVE-2026-34763
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
CVE-2026-25500
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
CVE-2026-22860
Rack has a Directory Traversal via Rack:Directory
CVE-2025-61771
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
CVE-2025-61772
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
CVE-2025-61770
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
CVE-2025-61919
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
CVE-2025-49007
ReDoS Vulnerability in Rack::Multipart handle_mime_head
CVE-2025-32441
Rack session gets restored after deletion
CVE-2025-27111
Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
CVE-2025-25184
Possible Log Injection in Rack::CommonLogger
CVE-2024-26146
Rack Header Parsing leads to Possible Denial of Service Vulnerability
CVE-2024-25126
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
CVE-2024-26141
Rack has possible DoS Vulnerability with Range Header
CVE-2025-27610
Local File Inclusion in Rack::Static
CVE-2020-8184
Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names
CVE-2019-16782
Possible Information Leak / Session Hijack Vulnerability in Rack
CVE-2020-8161
Directory traversal in Rack::Directory app bundled with Rack
CVE-2024-39316
Rack ReDoS Vulnerability in HTTP Accept Headers Parsing
CVE-2022-44570
Denial of service via header parsing in Rack
CVE-2023-27530
Rack has possible DoS Vulnerability in Multipart MIME parsing
CVE-2023-27539
Possible Denial of Service Vulnerability in Rack's header parsing
CVE-2013-0184
Rack vulnerable to Denial of Service
CVE-2013-0263
Rack arbitrary code execution via timing attack
CVE-2013-0183
Rack rubygems receiving excessively long lines triggers out-of-memory error
CVE-2015-3225
Rack vulnerable to Denial of Service via large parameter depth request
GHSA-9vc2-p34x-jhxh
Moderate severity vulnerability that affects rack
CVE-2022-44572
Denial of service via multipart parsing in Rack
CVE-2022-44571
Denial of Service Vulnerability in Rack Content-Disposition parsing
CVE-2011-5036
Rack Gem Subject to Denial of Service via Hash Collisions
CVE-2012-6109
Rack vulnerable to REDoS
CVE-2013-0262
Rack Vulnerable to Path Traversal
CVE-2022-30123
Possible shell escape sequence injection vulnerability in Rack
CVE-2022-30122
Denial of Service Vulnerability in Rack Multipart Parsing
CVE-2018-16471
Rack vulnerable to Cross-site Scripting
CVE-2018-16470
Rack vulnerable to Denial of Service
Browse more RubyGems advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes