pkg:RubyGems/rack
共 50 筆 CVECRITICAL1HIGH23MEDIUM19
✅ 檢查你的版本
所有已知漏洞
- from 0, < 2.0.9.1
- from 0, < 2.1.3
- HIGH7.5CVE-2026-34829Rack's multipart parsing without Content-Length header allows unbounded chunked file uploadsfrom 0, < 2.2.23
- HIGH7.5CVE-2026-34230Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding headerfrom 0, < 2.2.23
- HIGH7.5CVE-2026-34827Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters>= 3.0.0.beta1, < 3.1.21
- from 0, < 2.2.23
- from 0, < 2.2.22
- HIGH7.5CVE-2025-61919Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingfrom 0, < 2.2.20
- HIGH7.5CVE-2025-61772Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)from 0, < 2.2.19
- HIGH7.5CVE-2025-61771Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)from 0, < 2.2.19
- from 0, < 2.2.19
- HIGH7.5CVE-2025-59830Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parametersfrom 0, < 2.2.18
- from 0, < 2.2.14
- from 0, < 2.2.13
- from 0, < 2.2.12
- >= 3.0.0, < 3.0.9.1
- >= 3.0.0, < 3.0.9.1
- from 0, < 2.0.9.3
- >= 2.0.0, < 2.0.9.2
- >= 1.5.0, < 2.0.9.2
- >= 2.0.0, < 2.0.9.2
- >= 1.2, < 2.0.9.1
- from 0, < 2.1.4
- >= 2.0.4, < 2.0.6
- from 0, < 2.2.11
- >= 3.1.0, < 3.1.5
- from 0, < 1.6.12
- >= 2.0.0, < 2.0.6
- MEDIUM5.9CVE-2026-34830Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirectfrom 0, < 2.2.23
- from 0, < 2.2.20
- MEDIUM5.4CVE-2026-25500Stored XSS in Rack::Directory via javascript: filenames rendered into anchor hreffrom 0, < 2.2.22
- MEDIUM5.3CVE-2026-34763Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directoryfrom 0, < 2.2.23
- MEDIUM5.3CVE-2026-26961Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.from 0, < 2.2.23
- MEDIUM5.3CVE-2026-34826Rack's multipart byte range processing allows denial of service via excessive overlapping rangesfrom 0, < 2.2.23
- from 0, < 2.2.23
- >= 3.1.0, < 3.1.16
- >= 3.0.0, < 3.0.9.1
- >= 2.0.0, < 2.2.6.4
- MEDIUM4.8CVE-2026-34835Rack::Request accepts invalid Host characters, enabling host allowlist bypass>= 3.0.0.beta1, < 3.1.21
- from 0, < 2.2.23
- >= 3.0.0.beta1, < 3.1.21
- MEDIUM4.8CVE-2026-26962Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values>= 3.2.0, < 3.2.6
- from 0, < 2.2.14
- from 0, < 1.1.3
- >= 1.5.0, < 1.5.2
- >= 1.1.0, < 1.1.5
- from 0, < 1.1.4
- >= 1.5.0, < 1.5.2
- >= 1.3.0, < 1.3.8
- >= 1.5.0, < 1.5.4