CVE-2026-34835 affects Rack versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, where Rack::Request improperly parses the Host header, allowing non-RFC compliant characters. This vulnerability enables host header poisoning, potentially leading to incorrect link generation, redirects, or origin validation in applications that use `req.host`, `req.url`, or `req.base_url`. Rated Medium severity (CVSS 6.5) with a low attack complexity and network vector, it can impact confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.1.21CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* | ||
>= 3.2.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.