Linuxsecurity Multiple Vulnerabilities Discovered in Rack Affecting Ubuntu Releases
Article Content
- •Multiple vulnerabilities in Rack affect Ubuntu versions 20.04 LTS to 25.10.
- •Critical issues include potential denial of service and information disclosure.
- •Users must update to the latest package versions to secure their systems.
On April 17, 2026, multiple vulnerabilities in the Rack web server interface were disclosed, affecting several versions of Ubuntu, including 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. The vulnerabilities include improper parsing of regular expressions (CVE-2026-26961), mishandling of multipart headers (CVE-2026-26962), and incorrect handling of the Forwarded header (CVE-2026-32762). These issues could allow attackers to bypass network security filters, cause denial of service, or manipulate header values. Other vulnerabilities could lead to excessive CPU consumption and potential information disclosure. The affected versions span from Ubuntu 14.04 LTS to 25.10, indicating a broad impact across multiple releases. Users are advised to update their systems to the latest package versions to mitigate these vulnerabilities. The vulnerabilities were published on April 2, 2026, and are now being actively addressed by the community.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-26961 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…