CVE-2025-61780 is an information disclosure vulnerability in Rack, a Ruby web server interface, affecting versions prior to 2.2.20, 3.1.18, and 3.2.3. When Rack::Sendfile is used with a proxy supporting x-sendfile headers (like Nginx), specially crafted client headers can trick Rack into miscommunicating with the proxy, leading to unintended internal requests that bypass proxy access restrictions. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and can expose sensitive internal application routes, though it does not allow arbitrary file reads. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.20CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.0.0, < 3.1.18CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.3CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.