Rack Cors Project maintains a middleware library for handling Cross-Origin Resource Sharing (CORS) policy in Ruby and Rack-based web applications, with a narrow product footprint centered on the Rack-CORS gem itself. The vendor's reported vulnerabilities reflect typical issues in policy-enforcement middleware where permissiveness or parsing gaps can inadvertently broaden access; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rack Cors Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11173HIGH Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trus | Jul 13, 2017 | 8.8 | 29 | NO | NO |
CVE-2019-18978MEDIUM An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matchi | Nov 14, 2019 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rack Cors Project.
Media articles that mention a CVE ID that affects a product developed by Rack Cors Project — matched by CVE ID, not by vendor name.