CVE-2026-34785
rack rack, Red Hat Satellite 6
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and...
- CVSS
- 7.5
- EPSS
- 0.39% 31.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.03