CVE-2026-34830 | Rack up to 2.2.22/3.1.20/3.2.5 Regular Expression Rack::Sendfile X-Accel-Mapping permissive regular expression (GHSA-qv7j-4883-hwh7 / EUVD-2026-18390)
A vulnerability was found in Rack up to 2.2.22/3.1.20/3.2.5. It has been declared as problematic. Affected by this vulnerability is the function Rack::Sendfile of the component Regular Expression Handler. The manipulation of the argument X-Accel-Mapping results in permissive regular expression.
This vulnerability was named CVE-2026-34830. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.