CVE Explorer
CVE-2026-34835
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed. This can lead to host header poisoning in applications that use req.host, req.url,
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"rack","vendor":"rack","versions":[{"status":"affected","version":">= 3.0.0.beta1, < 3.1.21"},{"status":"affected","version":">= 3.2.0, < 3.2.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:487afdcca5e8ce2b25019a2c319ee0c6423920aa8d725eedf9d1ed0e664a4524 · sha256:fef5779a35be6c36… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:487afdcca5e8ce2b25019a2c319ee0c6423920aa8d725eedf9d1ed0e664a4524 · sha256:fef5779a35be6c36… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1286","description":"CWE-1286: Improper Validation of Syntactic Correctness of Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:487afdcca5e8ce2b25019a2c319ee0c6423920aa8d725eedf9d1ed0e664a4524 · sha256:fef5779a35be6c36… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/rack/rack/security/advisories/GHSA-g2pf-xv49-m2h5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/rack/rack/security/advisories/GHSA-g2pf-xv49-m2h5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:487afdcca5e8ce2b25019a2c319ee0c6423920aa8d725eedf9d1ed0e664a4524 · sha256:fef5779a35be6c36… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.