CVE-2026-34763
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex metacharacters such as +, *, or ., the prefix stripping can fail and the generated directory listing may expose the full filesystem path in the HTML output. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
- Rack
- < 2.2.23, 3.1.21, 3.2.6
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-625
- NVD status
- Analyzed
- Published
- 2026-04-02
CVE-2026-34763 at NVD
No indexed exploits for CVE-2026-34763 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-34763 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.