FlawAtlas
Search the atlas
UBUNTU-CVE-2024-26146 Moderate

UBUNTU-CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

Exploit probability Not scored
Published February 29, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS ruby-rack

4 explicit affected versions

Ubuntu:24.04:LTS ruby-rack

2 explicit affected versions

Ubuntu:Pro:14.04:LTS ruby-rack

7 explicit affected versions

Ubuntu:Pro:16.04:LTS ruby-rack

9 explicit affected versions

Ubuntu:Pro:18.04:LTS ruby-rack

7 explicit affected versions

Ubuntu:Pro:20.04:LTS ruby-rack

7 explicit affected versions

Ubuntu:Pro:22.04:LTS ruby-rack

7 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

View original source

05 / REFERENCES

Further evidence