CVE-2026-34786

EUVD-2026-18384
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, while the underlying file-serving path is decoded before the file is served. As a result, a request for a URL-encoded variant of a static path can serve the same file without the headers that header_rules were intended to apply. In deployments that rely on Rack::Static to attach security-relevant response headers to static content, this can allow an attacker to bypass those headers by requesting an encoded form of the path. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
rackrack
𝑥
< 2.2.23
rackrack
3.0.0 ≤
𝑥
< 3.1.21
rackrack
3.2.0 ≤
𝑥
< 3.2.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-rack
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
3.2.6-2
fixed
sid
3.2.6-2
fixed
trixie
vulnerable
trixie (security)
vulnerable
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
rmt-server
suse enterprise sap 15 SP7
2.27-150700.3.20.1
fixed
suse enterprise server 15 SP4
2.27-150400.3.54.1
fixed
suse enterprise server 15 SP7
2.27-150700.3.20.1
fixed
rmt-server-config
suse enterprise sap 15 SP7
2.27-150700.3.20.1
fixed
suse enterprise server 15 SP4
2.27-150400.3.54.1
fixed
suse enterprise server 15 SP7
2.27-150700.3.20.1
fixed
rmt-server-pubcloud
suse enterprise server 15 SP4
2.27-150400.3.54.1
fixed