CVE-2026-34763
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex metacharacters such as +, *, or ., the prefix stripping can fail and the generated directory listing may expose the full filesystem path in the HTML output. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-625
- Published
- 2026-04-02
- Last modified
- 2026-04-02
Affected products
- rack rack
- rack rack
- rack rack
Weakness type
Related vulnerabilities
- CVE-2026-79965 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-83618 — xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
- CVE-2026-83617 — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
- CVE-2026-83609 — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
- CVE-2026-82726 — AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant
- CVE-2026-55536 — Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
- CVE-2026-73845 — CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
- CVE-2026-19278 — Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings