CVE-2026-34831 is a medium-severity vulnerability affecting Rack, a Ruby web server interface, in versions prior to 2.2.23, 3.1.21, and 3.2.6. The flaw occurs when Rack::Files#fail incorrectly calculates the Content-Length header for responses containing multibyte UTF-8 characters, leading to a mismatch between the declared and actual content size. An attacker can remotely trigger this by requesting a non-existent path with percent-encoded UTF-8 characters, potentially causing HTTP response framing issues and desynchronization. Rated with a CVSS score of 4.8 (Medium) and high attack complexity, its primary impact is on data integrity and confidentiality. Currently, there is no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.23CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.