CVE-2026-22860Disclosure(rack / rack)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch rack rack systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-548

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rack

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
rack

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-23: 1Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-27: 102-1802-2302-27
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-231
Disclosure1
2026-02-271
Patch1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Patch

    Ubuntu fixes critical Rack path traversal and code execution flaws (CVE-2026-22860, CVE-2026-25500) impacting 25.10, 24.04 LTS, 22.04 LTS, 20.04 LTS. Users should update ruby-rack packages. https://threatcluster.io/cluster/critical-path-traversal-and-code-execution-vulnerabilities-i-8be99bdd

    Post summary

    Ubuntu has released updates for critical Rack path traversal and code execution vulnerabilities (CVE-2026-22860, CVE-2026-25500) affecting multiple releases; users should update the ruby-rack package.

    0001151
    83 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-22860 (rack): Rack has a Directory Traversal via Rack:Directory https://rubysec.com/advisories/CVE-2026-22860/

    Post summary

    RubySec announces a directory traversal vulnerability (CVE-2026-22860) in Rack, specifically affecting the Rack:Directory component.

    00010142
    2.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22860 Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded pa… https://www.cve.org/CVERecord?id=CVE-2026-22860

    Post summary

    The post reports CVE‑2026‑22860, a path traversal flaw in Rack::Directory before specific releases, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000139
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprackrack-ruby-

Explore more