Description:
Rack has a Directory Traversal via Rack:Directory. (CVE-2026-22860)
Rack's Stored XSS in Rack::Directory via javascript: filenames rendered
into anchor href. (CVE-2026-25500)
- https://bugs.mageia.org/show_bug.cgi?id=35285
- https://lists.debian.org/debian-security-announce/2026/msg00089.html
- https://www.cve.org/CVERecord?id=CVE-2026-22860
- https://www.cve.org/CVERecord?id=CVE-2026-25500
- 9/core/ruby-rack-2.2.22-1.mga9
Get the latest Linux and open source security news straight to your inbox.