« Volver al listado

CVE-2026-34830

Estado: AnalizadaAlta (7.5)—

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting file paths for X-Accel-Redirect. Because the header value is not escaped, an attacker who can supply X-Accel-Mapping to the backend can inject regex metacharacters and control the generated X-Accel-Redirect response header. In deployments using Rack::Sendfile with x-accel-redirect, this can allow an attacker to cause nginx to serve unintended files from configured internal locations. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/PR:N/UI:N indica red sin autenticación (T1190). La inyección de metacaracteres en X-Accel-Mapping permite leer archivos no autorizados del servidor (T1005). Rack::Sendfile expone la aplicación web a explotación remota de lectura de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34830",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34830",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-02T18:59:36.006369Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "rack",
          "product": "rack",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.2.23"
            },
            {
              "status": "affected",
              "version": ">= 3.0.0.beta1, < 3.1.21"
            },
            {
              "status": "affected",
              "version": ">= 3.2.0, < 3.2.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-02T17:16:26.267",
  "references": [
    {
      "url": "https://github.com/rack/rack/security/advisories/GHSA-qv7j-4883-hwh7",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-625"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting file paths for X-Accel-Redirect. Because the header value is not escaped, an attacker who can supply X-Accel-Mapping to the backend can inject regex metacharacters and control the generated X-Accel-Redirect response header. In deployments using Rack::Sendfile with x-accel-redirect, this can allow an attacker to cause nginx to serve unintended files from configured internal locations. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6."
    },
    {
      "lang": "es",
      "value": "Rack es una interfaz modular de servidor web Ruby. Antes de las versiones 2.2.23, 3.1.21 y 3.2.6, Rack::Sendfile#map_accel_path interpola el valor del encabezado de solicitud X-Accel-Mapping directamente en una expresión regular al reescribir rutas de archivo para X-Accel-Redirect. Debido a que el valor del encabezado no se escapa, un atacante que puede proporcionar X-Accel-Mapping al backend puede inyectar metacaracteres de expresiones regulares y controlar el encabezado de respuesta X-Accel-Redirect generado. En implementaciones que utilizan Rack::Sendfile con x-accel-redirect, esto puede permitir a un atacante hacer que nginx sirva archivos no deseados desde ubicaciones internas configuradas. Este problema ha sido parcheado en las versiones 2.2.23, 3.1.21 y 3.2.6."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD5DE7DE-3A8B-4064-A7D5-1E117A101E81",
              "versionEndExcluding": "2.2.23"
            },
            {
              "criteria": "cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6948AAA6-873D-46BA-AA22-4C81138128E1",
              "versionEndExcluding": "3.1.21",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FB592AD-E826-49BE-AC6D-E5F55FDCC96E",
              "versionEndExcluding": "3.2.6",
              "versionStartIncluding": "3.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}