CVE-2026-34827 is a high-severity denial of service vulnerability affecting Rack, a Ruby web server interface, in versions 3.0.0.beta1 through 3.1.20 and 3.2.0 through 3.2.5. This flaw allows an unauthenticated attacker to remotely trigger excessive CPU usage by sending a crafted multipart form-data request containing numerous backslash-escaped parameter values. The inefficient parsing of these values leads to super-linear processing, resulting in a denial of service condition for affected applications. With a CVSS score of 7.5 (High), the attack complexity is low. There is currently no evidence of active exploitation or public exploit code, though the vulnerability has received minor community discussion, and patches are available in Rack versions 3.1.21 and 3.2.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.