CVE-2026-39324Disclosure(rack / rack-session)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch rack rack-session systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. This allows an unauthenticated attacker to supply a crafted session cookie that is accepted as valid session data without knowledge of any configured secret. Because this mechanism is used to load session state, an attacker can manipulate session contents and potentially gain unauthorized access. This vulnerability is fixed in 2.1.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-345CWE-502CWE-565

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rack-session

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-07); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
rack-session

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-07: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 2Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 104-0704-0804-09
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure2General1
2026-04-082
Patch2
2026-04-091
Disclosure1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: A critical authentication bypass #vulnerability in #Rack Session allows unauthenticated attackers to forge session cookies and gain unauthorized access. #CVE-2026-39324 CVSS(4.0): 9.3. Read the advisory https://github.com/rack/rack-session/security/advisories/GHSA-33qg-7wpp-89cq and #Patch #Patch #Patch

    Post summary

    The tweet announces CVE‑2026‑39324, a critical authentication bypass vulnerability (CVSS 9.5) in Rack Session, and directs readers to the official advisory for the available patch.

    01000216
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39324 CVE-2026-39324 Rack::Session::Cookie decrypt failure falls back to accepting unencrypted cookies Advisory GHSA-33qg-7wpp-89cq Package rack-session (RubyGems) Affected <= 2.1.1 Patched... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39324

    Post summary

    CVE-2026-39324 is a vulnerability in rack-session (≤2.1.1) where decryption failure causes the system to accept unencrypted cookies, and a patch has been released.

    0000159
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A vulnerability in `Rack::Session::Cookie` (CVE-2026-39324) permits session forgery and `Marshal` deserialization on decrypt failure. This affects `Ruby` web applications. Further details are available. #Ruby #WebSecurity #CVE https://www.pulsepatch.io/posts/cve-2026-39324-rack-session-cookie-forgery-deserialization

    Post summary

    A new vulnerability (CVE‑2026‑39324) in Rack::Session::Cookie enables session forgery and unsafe Marshal deserialization; no PoC, exploit code, active use, or patch was mentioned.

    0000066
    11 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical Rack::Session::Cookie flaw: CVE-2026-39324 Apps using the secrets configuration may be exposed to session forgery and unauthorized access. Update to the patched version now. 🔗 https://vulert.com/vuln-db/CVE-2026-39324 #CyberSecurity #RackSessionCookie #CVE202639324 #Vulert

    Post summary

    A critical Rack::Session::Cookie session forgery vulnerability (CVE-2026-39324) is disclosed, and users are urged to patch immediately.

    0000040
    124 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39324 Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configur… https://www.cve.org/CVERecord?id=CVE-2026-39324

    Post summary

    The notice announces CVE‑2026‑39324, a decryption failure handling issue in Rack::Session::Cookie, without any PoC, exploit details, or patch information.

    0000092
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2026-39324: Rack::Session::Cookie secrets: d... Failed decryption fallback to default decoder = instant session forgery without secrets + potential RCE via Marshal des... https://zerodaysignal.com/vulnerability/CVE-2026-39324 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑39324 exposes a fallback mechanism in Rack::Session::Cookie that can enable session forgery and potentially RCE via Marshal deserialization. A link to ZeroDaySignal suggests PoC availability, but no evidence of active exploitation or mitigation is provided.

    0000080
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprackrack-session-ruby-

Explore more