CVE-2026-34826 is a denial-of-service vulnerability affecting Rack, a Ruby web server interface, in versions prior to 2.2.23, 3.1.21, and 3.2.6. An unauthenticated attacker can exploit this by sending HTTP Range headers with numerous small, overlapping byte ranges, causing disproportionate CPU, memory, I/O, and bandwidth consumption in Rack file-serving paths. This issue is rated Medium severity with a CVSS score of 5.3, indicating a low attack complexity and no required privileges or user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.23CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.