Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26961

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type header contains multiple boundary parameters, Rack selects the last one rather than the first. In deployments where an upstream proxy, WAF, or intermediary interprets the first boundary parameter, this mismatch can allow an attacker to smuggle multipart content past upstream inspection and have Rack parse a different body structure than the intermediary validated. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

A flaw was found in Rack, a modular Ruby web server interface. A remote attacker can exploit a vulnerability in Rack::Multipart::Parser by crafting a Content-Type header with multiple boundary parameters. This allows the attacker to bypass security inspections performed by upstream proxies or Web Application Firewalls (WAFs), leading to the Rack application processing different multipart content than what was validated by the intermediary. This content smuggling can enable unauthorized actions or data manipulation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6rubygem-rackNot affected
Red Hat Satellite 6rubygem-rack-testNot affected
Red Hat Satellite 6satellite-capsule:el8/rubygem-rackNot affected
Red Hat Satellite 6satellite:el8/rubygem-rack-testNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2454483github.com/rack/rack: Rack: Content smuggling via multipart boundary parsing mismatch

EPSS

Процентиль: 17%
0.00253
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
4 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type header contains multiple boundary parameters, Rack selects the last one rather than the first. In deployments where an upstream proxy, WAF, or intermediary interprets the first boundary parameter, this mismatch can allow an attacker to smuggle multipart content past upstream inspection and have Rack parse a different body structure than the intermediary validated. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

CVSS3: 3.7
nvd
4 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type header contains multiple boundary parameters, Rack selects the last one rather than the first. In deployments where an upstream proxy, WAF, or intermediary interprets the first boundary parameter, this mismatch can allow an attacker to smuggle multipart content past upstream inspection and have Rack parse a different body structure than the intermediary validated. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

CVSS3: 3.7
debian
4 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...

CVSS3: 5.3
github
4 месяца назад

Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость модульного интерфейса веб-сервера Rack языка программирования Ruby, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 17%
0.00253
Низкий

3.7 Low

CVSS3