CVE-2026-34830 is a medium-severity vulnerability affecting Rack versions prior to 2.2.23, 3.1.21, and 3.2.6, specifically within the Rack::Sendfile component when used with x-accel-redirect. It stems from unescaped regular expression interpolation, allowing an attacker to inject metacharacters via the X-Accel-Mapping header. This network-based attack, with high complexity, could lead to Nginx serving unintended internal files, resulting in a high confidentiality impact (CVSS 5.9). Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.23CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.