Multiple Vulnerabilities Discovered in Rack Affecting Ubuntu Releases

Multiple Vulnerabilities Discovered in Rack Affecting Ubuntu Releases

First seen 17 Apr 2026, 07:01 UTC UbuntuLinuxsecurity 86% similarity 57.9

Article Content

Browse articles
ThreatCluster

On April 17, 2026, multiple vulnerabilities in the Rack web server interface were disclosed, affecting several versions of Ubuntu, including 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. The vulnerabilities include improper parsing of regular expressions (CVE-2026-26961), mishandling of multipart headers (CVE-2026-26962), and incorrect handling of the Forwarded header (CVE-2026-32762). These issues could allow attackers to bypass network security filters, cause denial of service, or manipulate header values. Other vulnerabilities could lead to excessive CPU consumption and potential information disclosure. The affected versions span from Ubuntu 14.04 LTS to 25.10, indicating a broad impact across multiple releases. Users are advised to update their systems to the latest package versions to mitigate these vulnerabilities. The vulnerabilities were published on April 2, 2026, and are now being actively addressed by the community.

Key Points: • Multiple vulnerabilities in Rack affect Ubuntu versions 20.04 LTS to 25.10. • Critical issues include potential denial of service and information disclosure. • Users must update to the latest package versions to secure their systems.

ThreatCluster AI How this analysis works

Timeline

2026-04-02
CVE-2026-26961, CVE-2026-26962, CVE-2026-32762 published
2026-04-02
CVE-2026-34830 published
2026-04-02
CVE-2026-34786 published
2026-04-02
CVE-2026-34826 published
2026-04-02
CVE-2026-34829 published
2026-04-02
CVE-2026-34230 published
2026-04-02
CVE-2026-34785 published
2026-04-02
CVE-2026-34827 published
2026-04-02
CVE-2026-34831 published
2026-04-02
CVE-2026-34763 published

Community

Browse all →

Tracked Entities in This Story