Rack
Vendor:
First CVE: Dec 30, 2011 · Active for 14 years
50
Total CVEs
More Total CVEs than 91% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2011
14 years ago
Most Recent CVE
Apr 2, 2026
113 days ago
CVE Severity & Scoring
Rack50 CVEs
46%
52%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network43 (86.0%)
Unknown7 (14.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (82.0%)
High2 (4.0%)
Unknown7 (14.0%)
User Interaction
None41 (82.0%)
Unknown7 (14.0%)
Required2 (4.0%)
Privileges Required
Low4 (8.0%)
High0 (0.0%)
None39 (78.0%)
Unknown7 (14.0%)
Top CVEs
Signals from CVEs in this product scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25126HIGH Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible deni | Feb 29, 2024 | 7.5 | 40 | NO | NO |
CVE-2026-34826HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of in | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-34785HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-34230HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding values with quadratic time comp | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2020-8161HIGH A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack wh | Jul 2, 2020 | 8.6 | 29 | NO | NO |
CVE-2026-34827HIGH Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart | Apr 2, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-34829HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is | Apr 2, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-22860HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request | Feb 18, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-61772HIGH Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header | Oct 7, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-61770HIGH Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the first | Oct 7, 2025 | 7.5 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (50 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (50 CVEs).
Media Mentions
Signals from CVEs in this product scope (50 CVEs).
Top CNAs Publishing CVEs For Rack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.5 | 1 | 7.5 | 2.0% | 0 | 0 |
| 2.0.4 | 1 | 7.5 | 2.0% | 0 | 0 |
| 1.6.1 | 1 | 5.0 | 7.8% | 0 | 0 |
| 1.6.0 | 1 | 5.0 | 7.8% | 0 | 0 |
| 1.5.1 | 2 | 4.7 | 4.1% | 0 | 0 |
| 1.5.0 | 2 | 4.7 | 4.1% | 0 | 0 |
| 1.4.4 | 2 | 4.7 | 4.1% | 0 | 0 |
| 1.4.3 | 3 | 4.6 | 3.5% | 0 | 0 |
| 1.4.2 | 4 | 4.7 | 3.6% | 0 | 0 |
| 1.4.1 | 5 | 4.6 | 3.4% | 0 | 0 |
| 1.4.0 | 5 | 4.6 | 3.4% | 0 | 0 |
| 1.3.9 | 1 | 5.1 | 5.3% | 0 | 0 |
| 1.3.8 | 2 | 4.7 | 3.9% | 0 | 0 |
| 1.3.7 | 3 | 4.8 | 3.8% | 0 | 0 |
| 1.3.6 | 4 | 4.7 | 3.5% | 0 | 0 |
| 1.3.5 | 5 | 4.7 | 3.6% | 0 | 0 |
| 1.3.4 | 5 | 4.7 | 3.6% | 0 | 0 |
| 1.3.3 | 5 | 4.7 | 3.6% | 0 | 0 |
| 1.3.2 | 5 | 4.7 | 3.6% | 0 | 0 |
| 1.3.1 | 5 | 4.7 | 3.6% | 0 | 0 |