CVE-2026-34829 affects Rack, a modular Ruby web server interface, specifically versions prior to 2.2.23, 3.1.21, and 3.2.6. The vulnerability allows an unauthenticated attacker to trigger a denial of service by sending multipart/form-data requests without a Content-Length header, enabling unbounded streaming of data directly to disk. This high-severity issue (CVSS 7.5, AV:N/AC:L/A:H) has low attack complexity and can lead to complete disk exhaustion on affected systems. There is currently no evidence of active exploitation, nor are public exploit modules available in common repositories like Metasploit or ExploitDB, with minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.23CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.