PT-2026-29841 · Rack+2 · Rack+2
Wtn
·
Published
2026-04-02
·
Updated
2026-04-17
·
CVE-2026-26962
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rack versions 3.2.0 through 3.2.5
Description
Rack’s
Rack::Multipart::Parser incorrectly unfolds folded multipart part headers. When a multipart header contains an obs-fold sequence, Rack preserves the embedded CRLF in parsed parameter values such as filename or name instead of removing the folded line break during unfolding. This can lead to applications reusing these values in HTTP response headers being vulnerable to downstream header injection or response splitting.Recommendations
Update to Rack version 3.2.6 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Rack
Ubuntu