Visit Rails NES Home Page

Rack 1.6 Release Notes

8 versions

Changelog and Release Notes for the NES version of Rack 1.6

Mar 4, 2026
Latest: 1.6.13.26
69 Patched Vulnerabilities
VEX Statements

March 2026

Bug Fixes

  • CVE-2026-25500 - XSS injection via malicious filename in Rack::Directory.
  • CVE-2026-22860 - Directory traversal via root prefix bypass in Rack::Directory.

October 2025

1.6.13.25

Released on Oct 30, 2025

Notes

  • Removed an unnecessary warning caused by the last change ("unknown or unsafe x-sendfile variation"). This change has no security implications.

Bug Fixes

  • CVE-2025-61919 - Unbounded read in Rack::Request form parsing can lead to memory exhaustion.
  • CVE-2025-61780 - Improper handling of headers in Rack::Sendfile may allow proxy bypass.

Bug Fixes

  • CVE-2025-61772 - Multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion).
  • CVE-2025-61771 - Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion).
  • CVE-2025-61770 - Unbounded multipart preamble buffering enables DoS (memory exhaustion).

June 2025

1.6.13.22

Released on Jun 17, 2025

Bug Fixes

  • CVE-2025-49007 - Denial of service vulnerability in the Content-Disposition parsing component of Rack.

May 2025

Bug Fixes

  • CVE-2025-46727 - Unbounded parameter parsing in Rack::QueryParser can lead to memory exhaustion.
  • CVE-2025-32441 - Rack session can be restored after deletion.
  • CVE-2025-27610 - Local file inclusion in Rack::Static.

March 2025

Bug Fixes

February 2025

Notes

  • This is the initial release of Never-Ending Support (NES) for Rack v1.6.x.

Bug Fixes

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.