[ubuntu/questing-security] ruby-rack 3.1.16-0.1ubuntu0.3 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Thu Apr 16 16:28:21 UTC 2026


ruby-rack (3.1.16-0.1ubuntu0.3) questing-security; urgency=medium

  * SECURITY UPDATE: Security bypass in multipart parser
    - debian/patches/CVE-2026-26961.patch: Disallow boundary whitespace in
      lib/rack/multipart/parser.rb
    - CVE-2026-26961
  * SECURITY UPDATE: Header injection in multipart parser
    - debian/patches/CVE-2026-26962.patch: Enforce OBS unfolding in
      lib/rack/multipart/parser.rb
    - CVE-2026-26962
  * SECURITY UPDATE: Improper header parsing in forwarded_values
    - debian/patches/CVE-2026-32762.patch: Properly parse forwarded header in
      lib/rack/utils.rb
    - CVE-2026-32762
  * SECURITY UPDATE: Denial of service in select_best_encoding
    - debian/patches/CVE-2026-34230.patch: Disregard subsequent wildcards
      when an acceptable encoding has been selected in lib/rack/utils.rb
    - CVE-2026-34230
  * SECURITY UPDATE: Permissive regular expression in Directory
    - debian/patches/CVE-2026-34763.patch: Escape root before evaluating regex
      in lib/rack/directory.rb
    - CVE-2026-34763
  * SECURITY UPDATE: Information disclosure in Static
    - debian/patches/CVE-2026-34785.patch: Check that paths start with the
      static root prefix rather than merely containing them in
      lib/rack/static.rb
    - CVE-2026-34785
  * SECURITY UPDATE: Security bypass in applicable_rules
    - debian/patches/CVE-2026-34786.patch: Decode path before parsing to avoid
      bypassing header rules in lib/rack/static.rb
    - CVE-2026-34786
  * SECURITY UPDATE: Denial of service in byte_ranges
    - debian/patches/CVE-2026-34826.patch: Add a max_ranges argument to
      byte_ranges in lib/rack/utils.rb
    - CVE-2026-34826
  * SECURITY UPDATE: Denial of service in Parser
    - debian/patches/CVE-2026-34827.patch: Set maximum quoted escapes in
      lib/rack/multipart/parser.rb
    - debian/patches/CVE-2026-34829.patch: Set maximum value for
      content-length in lib/rack/multipart/parser.rb
    - CVE-2026-34827
    - CVE-2026-34829
  * SECURITY UPDATE: Permissive regular expression in map_accel_path
    - debian/patches/CVE-2026-34830.patch: Escape X-Accel-Mapping before
      interpreting as regular expression in lib/rack/sendfile.rb
    - CVE-2026-34830
  * SECURITY UPDATE: Improper handling of length in fail
    - debian/patches/CVE-2026-34831.patch: Set content-length to byte size
      rather than UTF-8 length in lib/rack/files.rb
    - CVE-2026-34831
  * SECURITY UPDATE: Security bypass in AUTHORITY
    - debian/patches/CVE-2026-34835.patch: Only match legal characters in
      hostname in lib/rack/request.rb
    - CVE-2026-34835

Date: 2026-04-14 23:02:10.884630+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
Signed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list