rack
Rack provides a minimal, modular and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call.
Security Advisories for rack in rubygems
Moderate
6 months ago
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
rubygems
rack
Moderate
6 months ago
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
rubygems
rack
High
6 months ago
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
rubygems
rack
Moderate
6 months ago
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
rubygems
rack
High
6 months ago
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
rubygems
rack
Moderate
6 months ago
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
rubygems
rack
Moderate
6 months ago
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
rubygems
rack
Moderate
6 months ago
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
rubygems
rack
High
6 months ago
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
rubygems
rack
Moderate
6 months ago
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
rubygems
rack
High
6 months ago
Rack::Static prefix matching can expose unintended files under the static root
rubygems
rack
Moderate
7 months ago
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
rubygems
rack
High
12 months ago
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
rubygems
rack
High
12 months ago
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
rubygems
rack
High
12 months ago
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
rubygems
rack
High
12 months ago
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
rubygems
rack
High
about 1 year ago
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
rubygems
rack
Moderate
over 1 year ago
Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
rubygems
rack
Moderate
over 2 years ago
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
rubygems
rack
Low
over 2 years ago
Rack Header Parsing leads to Possible Denial of Service Vulnerability
rubygems
rack
Low
over 3 years ago
Possible Denial of Service Vulnerability in Rack's header parsing
rubygems
rack
Low
over 3 years ago
Denial of Service Vulnerability in Rack Content-Disposition parsing
rubygems
rack
Critical
over 4 years ago
Possible shell escape sequence injection vulnerability in Rack
rubygems
rack
Moderate
over 4 years ago
Rack Gem Subject to Denial of Service via Hash Collisions
maven, rubygems
org.jruby:jruby-parent, rack
High
over 6 years ago
Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names
rubygems
rack
Moderate
almost 7 years ago
Possible Information Leak / Session Hijack Vulnerability in Rack
rubygems
rack
Moderate
almost 9 years ago
Rack rubygems receiving excessively long lines triggers out-of-memory error
rubygems
rack
Moderate
almost 9 years ago
Rack vulnerable to Denial of Service via large parameter depth request
rubygems
rack