FlawAtlas
Search the atlas
UBUNTU-CVE-2024-26141 Moderate

UBUNTU-CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

Exploit probability Not scored
Published February 29, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS ruby-rack

4 explicit affected versions

Ubuntu:24.04:LTS ruby-rack

2 explicit affected versions

Ubuntu:Pro:14.04:LTS ruby-rack

7 explicit affected versions

Ubuntu:Pro:16.04:LTS ruby-rack

9 explicit affected versions

Ubuntu:Pro:18.04:LTS ruby-rack

7 explicit affected versions

Ubuntu:Pro:20.04:LTS ruby-rack

7 explicit affected versions

Ubuntu:Pro:22.04:LTS ruby-rack

7 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.

View original source

05 / REFERENCES

Further evidence