Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34831

Опубликовано: 02 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.8

Описание

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains multibyte UTF-8 characters, the declared Content-Length is smaller than the number of bytes actually sent on the wire. Because Rack::Files reflects the requested path in 404 responses, an attacker can trigger this mismatch by requesting a non-existent path containing percent-encoded UTF-8 characters. This results in incorrect HTTP response framing and may cause response desynchronization in deployments that rely on the incorrect Content-Length value. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

РелизСтатусПримечание
devel

needed

esm-apps-legacy/xenial

not-affected

see notes
esm-apps/bionic

not-affected

see notes
esm-apps/focal

not-affected

see notes
esm-apps/jammy

released

2.1.4-5ubuntu1.2+esm3
esm-apps/xenial

not-affected

see notes
esm-infra-legacy/trusty

not-affected

see notes
jammy

needed

noble

released

2.2.7-1ubuntu0.7
questing

released

3.1.16-0.1ubuntu0.3

Показывать по

EPSS

Процентиль: 4%
0.00147
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
4 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains multibyte UTF-8 characters, the declared Content-Length is smaller than the number of bytes actually sent on the wire. Because Rack::Files reflects the requested path in 404 responses, an attacker can trigger this mismatch by requesting a non-existent path containing percent-encoded UTF-8 characters. This results in incorrect HTTP response framing and may cause response desynchronization in deployments that rely on the incorrect Content-Length value. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

CVSS3: 4.8
nvd
4 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains multibyte UTF-8 characters, the declared Content-Length is smaller than the number of bytes actually sent on the wire. Because Rack::Files reflects the requested path in 404 responses, an attacker can trigger this mismatch by requesting a non-existent path containing percent-encoded UTF-8 characters. This results in incorrect HTTP response framing and may cause response desynchronization in deployments that rely on the incorrect Content-Length value. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

CVSS3: 4.8
debian
4 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...

CVSS3: 4.8
github
4 месяца назад

Rack has Content-Length mismatch in Rack::Files error responses

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость модульного интерфейса веб-сервера Rack языка программирования Ruby, связанная с неправильной обработкой несоответствия параметра длины, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 4%
0.00147
Низкий

4.8 Medium

CVSS3