PT-2026-30806 · Unknown · Rack::Session

·

CVE-2026-39324

·

Published

2026-04-07

·

Updated

2026-04-28

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rack::Session versions 2.0.0 through 2.1.1
Description Rack::Session is a session management implementation for Rack. Versions 2.0.0 through 2.1.1 incorrectly handle decryption failures when configured with secrets. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. This allows an unauthenticated attacker to supply a crafted session cookie that is accepted as valid session data without knowledge of any configured secret. An attacker can manipulate session contents and potentially gain unauthorized access.
Recommendations Update Rack::Session to version 2.1.2 or later.

Exploit

Fix

RCE

Insufficient Verification of Data Authenticity

Improper Authentication

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09334
CVE-2026-39324
GHSA-33QG-7WPP-89CQ
OPENSUSE-SU-2026:10604-1
USN-8190-1
USN-8190-2

Affected Products

Rack::Session