PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-34829 rack CVE debrief

CVE-2026-34829 is a high-severity vulnerability in Rack, a modular Ruby web server interface. The vulnerability exists in Rack::Multipart::Parser, which fails to limit the size of multipart/form-data requests when the Content-Length header is absent, such as with HTTP chunked transfer encoding. This allows an unauthenticated attacker to stream large files and consume unbounded disk space, resulting in a denial of service condition for Rack applications that accept multipart form data. The issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6. Users are advised to upgrade to these versions to mitigate the vulnerability.

Vendor
rack
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-02
Original CVE updated
2026-07-24
Advisory published
2026-04-02
Advisory updated
2026-07-24

Who should care

Developers and administrators using Rack applications that accept multipart form data should be aware of this vulnerability. This includes users of Ruby on Rails, as Rack is a dependency. The vulnerability can be exploited by an unauthenticated attacker, making it a significant concern for applications exposed to the internet.

Technical summary

The vulnerability in Rack::Multipart::Parser allows for unbounded disk space consumption during multipart file uploads when the Content-Length header is missing. This is because the parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. For file parts, the uploaded body is written directly to a temporary file on disk without being constrained by an in-memory upload limit. An attacker can exploit this by streaming an arbitrarily large multipart file upload.

Defensive priority

High priority should be given to upgrading Rack to versions 2.2.23, 3.1.21, or 3.2.6. In the meantime, consider implementing compensating controls such as monitoring for large file uploads and setting limits on upload sizes.

Recommended defensive actions

  • Upgrade Rack to version 2.2.23, 3.1.21, or 3.2.6.
  • Implement monitoring for large file uploads.
  • Set limits on upload sizes as a compensating control.
  • Review application code for insecure direct object references.
  • Perform regular security audits and vulnerability assessments.

Evidence notes

The CVE record and NVD detail provide comprehensive information about the vulnerability. The vendor advisory on GitHub and Red Hat's security advisories offer additional context and mitigation strategies.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-34829 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-34829

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-34829 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34829

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/rack/rack/security/advisories/GHSA-8vqr-qjwx-82mw

    [email protected] - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-34829

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34829.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.