rack records
39 published records for vendor rack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption15
- CWE-1333 Inefficient Regular Expression Complexity3
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')3
- CWE-625 Permissive Regular Expression2
- CWE-436 Interpretation Conflict2
- CWE-770 Allocation of Resources Without Limits or Throttling2
The weakness classes this vendor ships most often: where to look.
CWEAll records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2024-25126No exploit | Rack ReDos in content type parsing (2nd degree polynomial)rack · rack · CWE-1333 | High7.5 | — | 35.4% | Feb 28, 2024 |
37Monitor | CVE-2026-39324Proof of concept | Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationrack · rack-session · CWE-287 | Critical9.3 | — | 0.3% | Apr 7, 2026 |
34Monitor | CVE-2024-35231No exploit | rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameterrack · rack-contrib · CWE-770 | High8.6 | — | 0.7% | May 27, 2024 |
31Monitor | CVE-2024-26146No exploit | Possible Denial of Service Vulnerability in Rack Header Parsingrack · rack · CWE-1333 | High7.5 | — | 2.0% | Feb 28, 2024 |
31Monitor | CVE-2023-27530No exploit | A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could alrack · rack · CWE-400 | High7.5 | — | 1.8% | Mar 10, 2023 |
30Monitor | CVE-2022-44570No exploit | A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0.rack · rack · CWE-400 | High7.5 | — | 1.6% | Feb 9, 2023 |
30Monitor | CVE-2022-44572No exploit | A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an arack · rack · CWE-400 | High7.5 | — | 1.6% | Feb 9, 2023 |
30Monitor | CVE-2024-26141No exploit | Possible DoS Vulnerability with Range Header in Rackrack · rack · CWE-400 | High7.5 | — | 1.6% | Feb 28, 2024 |
30Monitor | CVE-2022-44571No exploit | There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1.rack · rack · CWE-400 | High7.5 | — | 1.5% | Feb 9, 2023 |
30Monitor | CVE-2025-46727No exploit | Unbounded-Parameter DoS in Rack::QueryParserrack · rack · CWE-400 | High7.5 | — | 1.2% | May 7, 2025 |
30Monitor | CVE-2025-27610No exploit | Local File Inclusion in Rack::Staticrack · rack · CWE-23 | High7.5 | — | 1.2% | Mar 10, 2025 |
30Monitor | CVE-2025-61770No exploit | Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)rack · rack · CWE-400 | High7.5 | — | 0.9% | Oct 7, 2025 |
30Monitor | CVE-2025-61772No exploit | Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)rack · rack · CWE-400 | High7.5 | — | 0.9% | Oct 7, 2025 |
30Monitor | CVE-2026-22860No exploit | Rack has a Directory Traversal via Rack:Directoryrack · rack · CWE-22 | High7.5 | — | 0.7% | Feb 18, 2026 |
30Monitor | CVE-2026-34827No exploit | Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parserrack · rack · CWE-400 | High7.5 | — | 0.7% | Apr 2, 2026 |
30Monitor | CVE-2026-34829No exploit | Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Lengthrack · rack · CWE-400 | High7.5 | — | 0.7% | Apr 2, 2026 |
30Monitor | CVE-2025-61919No exploit | Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingrack · rack · CWE-400 | High7.5 | — | 0.6% | Oct 10, 2025 |
30Monitor | CVE-2025-59830No exploit | Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parametersrack · rack · CWE-400 | High7.5 | — | 0.6% | Sep 25, 2025 |
30Monitor | CVE-2025-61771No exploit | Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)rack · rack · CWE-400 | High7.5 | — | 0.6% | Oct 7, 2025 |
30Monitor | CVE-2026-34785No exploit | Rack: Local file inclusion in `Rack::Static` via URL Prefix Matchingrack · rack · CWE-187 | High7.5 | — | 0.5% | Apr 2, 2026 |
30Monitor | CVE-2026-34230No exploit | Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding headerrack · rack · CWE-400 | High7.5 | — | 0.5% | Apr 2, 2026 |
30Monitor | CVE-2026-34826No exploit | Rack: Unbounded Range Count in get_byte_ranges Enables DoSrack · rack · CWE-400 | High7.5 | — | 0.5% | Apr 2, 2026 |
30Monitor | CVE-2026-34830No exploit | Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginxrack · rack · CWE-625 | High7.5 | — | 0.4% | Apr 2, 2026 |
27Monitor | CVE-2025-27111No exploit | Escape Sequence Injection vulnerability in Rack lead to Possible Log Injectionrack · rack · CWE-93 | Medium6.9 | — | 0.8% | Mar 4, 2025 |
26Monitor | CVE-2024-39316No exploit | Rack ReDoS Vulnerability in HTTP Accept Headers Parsingrack · rack · CWE-1333 | Medium6.5 | — | 0.9% | Jul 2, 2024 |
- CVE-2024-2512641Plan
Rack ReDos in content type parsing (2nd degree polynomial)
HighCVSS 7.5No exploitEPSS 35%rack · rackFeb 28, 2024
- CVE-2026-3932437Monitor
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
CriticalCVSS 9.3Proof of conceptEPSS 0%rack · rack-sessionApr 7, 2026
- CVE-2024-3523134Monitor
rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter
HighCVSS 8.6No exploitEPSS 1%rack · rack-contribMay 27, 2024
- CVE-2024-2614631Monitor
Possible Denial of Service Vulnerability in Rack Header Parsing
HighCVSS 7.5No exploitEPSS 2%rack · rackFeb 28, 2024
- CVE-2023-2753031Monitor
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could al
HighCVSS 7.5No exploitEPSS 2%rack · rackMar 10, 2023
- CVE-2022-4457030Monitor
A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0.
HighCVSS 7.5No exploitEPSS 2%rack · rackFeb 9, 2023
- CVE-2022-4457230Monitor
A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an a
HighCVSS 7.5No exploitEPSS 2%rack · rackFeb 9, 2023
- CVE-2024-2614130Monitor
Possible DoS Vulnerability with Range Header in Rack
HighCVSS 7.5No exploitEPSS 2%rack · rackFeb 28, 2024
- CVE-2022-4457130Monitor
There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1.
HighCVSS 7.5No exploitEPSS 2%rack · rackFeb 9, 2023
- CVE-2025-4672730Monitor
Unbounded-Parameter DoS in Rack::QueryParser
HighCVSS 7.5No exploitEPSS 1%rack · rackMay 7, 2025
- CVE-2025-2761030Monitor
Local File Inclusion in Rack::Static
HighCVSS 7.5No exploitEPSS 1%rack · rackMar 10, 2025
- CVE-2025-6177030Monitor
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
HighCVSS 7.5No exploitEPSS 1%rack · rackOct 7, 2025
- CVE-2025-6177230Monitor
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
HighCVSS 7.5No exploitEPSS 1%rack · rackOct 7, 2025
- CVE-2026-2286030Monitor
Rack has a Directory Traversal via Rack:Directory
HighCVSS 7.5No exploitEPSS 1%rack · rackFeb 18, 2026
- CVE-2026-3482730Monitor
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
HighCVSS 7.5No exploitEPSS 1%rack · rackApr 2, 2026
- CVE-2026-3482930Monitor
Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
HighCVSS 7.5No exploitEPSS 1%rack · rackApr 2, 2026
- CVE-2025-6191930Monitor
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
HighCVSS 7.5No exploitEPSS 1%rack · rackOct 10, 2025
- CVE-2025-5983030Monitor
Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters
HighCVSS 7.5No exploitEPSS 1%rack · rackSep 25, 2025
- CVE-2025-6177130Monitor
Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
HighCVSS 7.5No exploitEPSS 1%rack · rackOct 7, 2025
- CVE-2026-3478530Monitor
Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching
HighCVSS 7.5No exploitEPSS 1%rack · rackApr 2, 2026
- CVE-2026-3423030Monitor
Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
HighCVSS 7.5No exploitEPSS 0%rack · rackApr 2, 2026
- CVE-2026-3482630Monitor
Rack: Unbounded Range Count in get_byte_ranges Enables DoS
HighCVSS 7.5No exploitEPSS 0%rack · rackApr 2, 2026
- CVE-2026-3483030Monitor
Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx
HighCVSS 7.5No exploitEPSS 0%rack · rackApr 2, 2026
- CVE-2025-2711127Monitor
Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
MediumCVSS 6.9No exploitEPSS 1%rack · rackMar 4, 2025
- CVE-2024-3931626Monitor
Rack ReDoS Vulnerability in HTTP Accept Headers Parsing
MediumCVSS 6.5No exploitEPSS 1%rack · rackJul 2, 2024