CCB Alert@CCBalertPatch
The tweet announces CVE‑2026‑39324, a critical authentication bypass vulnerability (CVSS 9.5) in Rack Session, and directs readers to the official advisory for the available patch.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-39324 is a vulnerability in rack-session (≤2.1.1) where decryption failure causes the system to accept unencrypted cookies, and a patch has been released.
PulsePatch.io@pulsepatchioDisclosure
A new vulnerability (CVE‑2026‑39324) in Rack::Session::Cookie enables session forgery and unsafe Marshal deserialization; no PoC, exploit code, active use, or patch was mentioned.
Vulert@vulert_officialPatch
A critical Rack::Session::Cookie session forgery vulnerability (CVE-2026-39324) is disclosed, and users are urged to patch immediately.
CVE@CVEnewDisclosure
The notice announces CVE‑2026‑39324, a decryption failure handling issue in Rack::Session::Cookie, without any PoC, exploit details, or patch information.
0day Signal@0dayPublishingGeneral
CVE‑2026‑39324 exposes a fallback mechanism in Rack::Session::Cookie that can enable session forgery and potentially RCE via Marshal deserialization. A link to ZeroDaySignal suggests PoC availability, but no evidence of active exploitation or mitigation is provided.