Sploitus

CVE-2026-22860

No indexed exploits for CVE-2026-22860 yet

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

Affected products
Linuxmint, Rack, Red Os, Ubuntu
Rack
< 2.2.22, 3.1.20, 3.2.5
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.7% (48th percentile)
Weakness
CWE-22, CWE-548
NVD status
Modified
Published
2026-02-18
CVE-2026-22860 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-22860 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-22860 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.