Several security issues were fixed in Rack.
Software Description:
- ruby-rack: modular Ruby webserver interface
Details:
Andrew Lacambra discovered that Rack did not properly parse certain regular
expressions. An attacker could possibly use this issue to bypass network
security filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)
William T. Nelson discovered that Rack did not handle multipart headers
correctly. An attacker could possibly use this issue to cause downstream
parsing issues or a denial of service. This issue only affected Ubuntu
25.10. (CVE-2026-26962)
It was discovered that Rack did not handle the Forwarded header correctly.
An attacker could possibly use this issue to manipulate header values. This
issue only affected Ubuntu 25.10. (CVE-2026-32762)
It was discovered that Rack could consume excessive CPU when handling
certain Accept-Encoding values. An attacker could possibly use this issue
to...
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 25.10
ruby-rack 3.1.16-0.1ubuntu0.3
Ubuntu 24.04 LTS
ruby-rack 2.2.7-1ubuntu0.7
Ubuntu 22.04 LTS
ruby-rack 2.1.4-5ubuntu1.2+esm3
Available with Ubuntu Pro
Ubuntu 20.04 LTS
ruby-rack 2.0.7-2ubuntu0.1+esm10
Available with Ubuntu Pro
Ubuntu 18.04 LTS
ruby-rack 1.6.4-4ubuntu0.2+esm10
Available with Ubuntu Pro
Ubuntu 16.04 LTS
ruby-rack 1.6.4-3ubuntu0.2+esm10
Available with Ubuntu Pro
Ubuntu 14.04 LTS
librack-ruby 1.5.2-3+deb8u3ubuntu1~esm11
Available with Ubuntu Pro
librack-ruby1.8 1.5.2-3+deb8u3ubuntu1~esm11
Available with Ubuntu Pro
librack-ruby1.9.1 1.5.2-3+deb8u3ubuntu1~esm11
Available with Ubuntu Pro
ruby-rack 1.5.2-3+deb8u3ubuntu1~esm11
Available with Ubuntu Pro
After a standard system update you need to restart any applications using
Rack to make all the necessary changes.https://ubuntu.com/security/notices/USN-8182-1
CVE-2026-26961, CVE-2026-26962, CVE-2026-32762, CVE-2026-34230,
CVE-2026-34763, CVE-2026-34785, CVE-2026-34786, CVE-2026-34826,
CVE-2026-34827, CVE-2026-34829, CVE-2026-34830, CVE-2026-34831,
CVE-2026-34835
Get the latest Linux and open source security news straight to your inbox.