CVE Explorer
CVE-2026-34763
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex metacharacters such as +, *, or ., the prefix stripping can fail and the generated directory listing may expose the full filesystem path in the HTML output. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"rack","vendor":"rack","versions":[{"status":"affected","version":"< 2.2.23"},{"status":"affected","version":">= 3.0.0.beta1, < 3.1.21"},{"status":"affected","version":">= 3.2.0, < 3.2.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:78f7f71d536db7d6a66e5ffb88577907ec35f09bb366c523fd937741d2a824d8 · sha256:fde9122c8a8af210… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:78f7f71d536db7d6a66e5ffb88577907ec35f09bb366c523fd937741d2a824d8 · sha256:fde9122c8a8af210… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-625","description":"CWE-625: Permissive Regular Expression","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:78f7f71d536db7d6a66e5ffb88577907ec35f09bb366c523fd937741d2a824d8 · sha256:fde9122c8a8af210… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/rack/rack/security/advisories/GHSA-7mqq-6cf9-v2qp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/rack/rack/security/advisories/GHSA-7mqq-6cf9-v2qp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78f7f71d536db7d6a66e5ffb88577907ec35f09bb366c523fd937741d2a824d8 · sha256:fde9122c8a8af210… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.