Skip to main content

Vendor/product archive

rack / rack-session CVEs

Beta · best-effort

1 CVEs tagged to rack / rack-session1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-39324

Published Apr 7, 2026

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secre…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1