Rack is a technology platform tracked across 5 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity June 22, 2026.
Rack is a Ruby webserver interface gem that acts as middleware between web servers and Ruby web frameworks (e.g., Rails, Sinatra). Its ubiquity in Ruby-based web stacks makes vulnerabilities in rubygem-rack significant, as a critical DoS exploit can impact many Ruby applications. A Fedora 42 update includes a fix for a critical Denial-of-Service in rubygem-rack, underscoring the importance of prompt patching in Ruby environments.
Ubuntu 25.10 and its LTS derivatives are affected by vulnerabilities in Rack, a Ruby webserver interface. CVE-2026-22860 allows for path traversal attacks that could leak sensitive information, while CVE-2026-25500…
On April 17, 2026, multiple vulnerabilities in the Rack web server interface were disclosed, affecting several versions of Ubuntu, including 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. The vulnerabilities include…
Multiple vulnerabilities affecting the Rack library, used for developing Ruby web applications, have been reported. Fedora 42 and 43 released updates to address a critical denial of service vulnerability in Rack 2.2.21…
Multiple versions of the Ruby Rack library have been found to have critical and moderate Denial of Service (DoS) vulnerabilities affecting Fedora distributions. Fedora 42 and 43 have released updates to address these…
SUSE has released updates addressing a critical buffer overflow vulnerability (CVE-2026-25506) in the munge package, affecting multiple SUSE Linux versions. The vulnerability, which was published on February 10, 2026,…