Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

CVE-2026-26961 (Low) detected in rack-3.1.16.gem

Đang mở Phù hợp với người mới
#276 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
68/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
ruby
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu bằng cách kiểm tra Gemfile.lock và vendor/cache/rack-3.1.16.gem, sau đó kiểm tra cách repository này làm mới các gem đã khóa và được lưu trong bộ nhớ đệm. Hoàn thành khi dependency sử dụng một bản phát hành Rack đã được vá được liệt kê trong issue và CVE không còn được báo cáo.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Mend: dependency security vulnerability

CVE-2026-26961 - Low Severity Vulnerability

Vulnerable Library - rack-3.1.16.gem

Rack provides a minimal, modular and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call.

Library home page: https://rubygems.org/gems/rack-3.1.16.gem

Path to dependency file: /Gemfile.lock

Path to vulnerable library: /vendor/cache/rack-3.1.16.gem

Dependency Hierarchy:

  • manageiq-style-1.3.3.gem (Root Library)
    • rubocop-rails-2.32.0.gem
      • ❌ rack-3.1.16.gem (Vulnerable Library)

Found in base branch: master

Vulnerability Details

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type header contains multiple boundary parameters, Rack selects the last one rather than the first. In deployments where an upstream proxy, WAF, or intermediary interprets the first boundary parameter, this mismatch can allow an attacker to smuggle multipart content past upstream inspection and have Rack parse a different body structure than the intermediary validated. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

Publish Date: 2026-04-02

URL: CVE-2026-26961

CVSS 3 Score Details (3.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-vgpv-f759-9wx3

Release Date: 2026-04-02

Fix Resolution: rack - 3.2.6,rack - 3.1.21,rack - 2.2.23


Step up your Open Source Security Game with Mend here

Ngôn ngữ chính
Ruby
Star
30
Fork
27
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của ManageIQ/linux_admin

Tất cả issue của ManageIQ/linux_admin

Issue tương tự

Thêm issue về Ruby

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.