CVE-2026-34785 is an information disclosure vulnerability in Rack::Static, a component of the Rack Ruby web server interface, affecting versions prior to 2.2.23, 3.1.21, and 3.2.6. This flaw allows unintended static files to be served due to an insecure prefix-based URL matching mechanism, potentially exposing sensitive data. Rated High with a CVSS score of 7.5, the vulnerability has low attack complexity and requires no user interaction, making it a significant risk for unauthenticated information disclosure. There is currently no evidence of active exploitation, nor are public exploit modules available, although the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.23CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.