CVE-2026-34830
MEDIUMRack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx
Title source: cnaDescription
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting file paths for X-Accel-Redirect. Because the header value is not escaped, an attacker who can supply X-Accel-Mapping to the backend can inject regex metacharacters and control the generated X-Accel-Redirect response header. In deployments using Rack::Sendfile with x-accel-redirect, this can allow an attacker to cause nginx to serve unintended files from configured internal locations. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/rack/rack/security/advisories/GHSA-qv7j-4883-hwh7
Scores
CVSS v3
5.9
EPSS
0.0005
EPSS Percentile
14.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-625
Status
published
Products (6)
rack/rack
< 2.2.23 (2 CPE variants)
rack/rack
>= 3.0.0.beta1, < 3.1.21
rack/rack
>= 3.2.0, < 3.2.6
rubygems/rack
0 - 2.2.23RubyGems
rubygems/rack
3.0.0.beta1 - 3.1.21RubyGems
rubygems/rack
3.2.0 - 3.2.6RubyGems
Published
Apr 02, 2026
Tracked Since
Apr 02, 2026