Debian DLA-4505-1 ruby-rack Critical Directory Listing XSS

User avatar
admin Verified Great Britain
Site Admin
Posts: 22286
Joined: Wed Jun 11, 2025 9:20 pm

Awards

Debian DLA-4505-1 ruby-rack Critical Directory Listing XSS

Post by admin Verified »

Two vulnerabilities were discovered in ruby-rack, a modular Ruby webserver interface. CVE-2026-22860 Rack::Directory's path check used a string prefix match on the expanded path. A request like /../root_example/ could escape the

Source: https://linuxsecurity.com/advisories/de ... -ruby-rack
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest