Host Header Poisoning Vulnerability in Rack Web Server Interface
CVE-2026-34835

4.8MEDIUM

Key Information:

Vendor

Rack

Status
Vendor
CVE Published:
2 April 2026

What is CVE-2026-34835?

The Rack web server interface is susceptible to host header poisoning due to improper parsing of the Host header in specific versions. It allows the inclusion of illegal characters that violate RFC-compliances, such as /, ?, #, and @. This vulnerability exposes applications relying on the parsed host value to security risks, enabling potential bypassing of host validation mechanisms in the URL generation and redirect processes. The issue has been addressed in newer versions, emphasizing the importance of updating to mitigate potential exploitation.

Affected Version(s)

rack >= 3.0.0.beta1, < 3.1.21 < 3.0.0.beta1, 3.1.21

rack >= 3.2.0, < 3.2.6 < 3.2.0, 3.2.6

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.