Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue. | |
| Title | Rack has a Directory Traversal via Rack:Directory | |
| Weaknesses | CWE-22 CWE-548 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-18T19:28:38.445Z
Reserved: 2026-01-12T16:20:16.746Z
Link: CVE-2026-22860
Updated: 2026-02-18T19:28:26.018Z
Status : Received
Published: 2026-02-18T19:21:43.933
Modified: 2026-02-18T19:21:43.933
Link: CVE-2026-22860
No data.
OpenCVE Enrichment
No data.