PT-2026-29809 · Rack+3 · Rack+3

·

CVE-2026-34230

·

Published

2026-04-02

·

Updated

2026-08-25

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rack versions prior to 2.2.23, 3.1.21, and 3.2.6
Description Rack::Utils.select best encoding processes Accept-Encoding values with quadratic time complexity when the header contains many wildcard (*) entries. Because this method is used by Rack::Deflater to choose a response encoding, an unauthenticated attacker can send a single request with a crafted Accept-Encoding header and cause disproportionate CPU consumption on the compression middleware path. This results in a denial of service condition for applications using Rack::Deflater. The attack does not require invalid HTTP syntax or large payload bodies. A single header-sized request is sufficient to reach the vulnerable code path.
Recommendations Update to Rack version 2.2.23, 3.1.21, or 3.2.6.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07728
CVE-2026-34230
GHSA-V569-HP3G-36WR
OPENSUSE-SU-2026:10508-1
OPENSUSE-SU-2026:21640-1
SUSE-SU-2026:1745-1
SUSE-SU-2026:1964-1
SUSE-SU-2026:23321-1
SUSE-SU-2026:2487-1
USN-8182-1

Affected Products

Linuxmint
Rack
Red Os
Ubuntu