CVE-2026-34763 affects Rack, a Ruby web server interface, in versions prior to 2.2.23, 3.1.21, and 3.2.6. The vulnerability allows for the exposure of full filesystem paths in directory listings due to improper handling of regex metacharacters in the configured root path by Rack::Directory. Rated as medium severity (CVSS 5.3), this issue has low attack complexity and requires no authentication or user interaction, enabling an unauthenticated attacker to remotely disclose sensitive information. There is no indication of active exploitation, and no public exploit code or significant community discussion has been identified for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.23CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.