{"api_version":"v1","generated_at":"2026-10-06T17:45:00+00:00","product":{"cve_count":32,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-rack-rack-6db2c23d6bec","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/rack","name":"Rack","next_cursor":null,"observations":[{"affected":">= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-26962","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26962","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T18:13:06.632Z","patch_url":"https://github.com/rack/rack/security/advisories/GHSA-rx22-g9mx-qrhv","primary_source":"","published":"2026-04-02T17:10:17.091Z"},{"affected":">= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34835","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34835","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T17:44:03.453Z","patch_url":"https://github.com/rack/rack/security/advisories/GHSA-g2pf-xv49-m2h5","primary_source":"","published":"2026-04-02T17:09:07.047Z"},{"affected":">= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34827","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34827","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:03:40.859Z","patch_url":"https://github.com/rack/rack/security/advisories/GHSA-v6x5-cg8r-vv6x","primary_source":"","published":"2026-04-02T17:07:48.279Z"},{"affected":">= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-32762","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32762","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T17:42:42.305Z","patch_url":"https://github.com/rack/rack/security/advisories/GHSA-qfgr-crr9-7r49","primary_source":"","published":"2026-04-02T17:06:50.819Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34830","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34830","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T18:59:46.589Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34830","primary_source":"","published":"2026-04-02T16:47:40.490Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34829","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34829","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:03:38.459Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34829","primary_source":"","published":"2026-04-02T16:46:47.357Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34826","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34826","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T18:13:27.375Z","patch_url":"https://github.com/rack/rack/security/advisories/GHSA-x8cg-fq8g-mxfx","primary_source":"","published":"2026-04-02T16:45:53.964Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34786","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34786","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T17:38:11.143Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34786","primary_source":"","published":"2026-04-02T16:44:59.694Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34785","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34785","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:03:43.203Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34785","primary_source":"","published":"2026-04-02T16:44:17.134Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34763","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34763","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T17:41:12.293Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34763","primary_source":"","published":"2026-04-02T16:43:42.189Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34831","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34831","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T17:48:11.330Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34831","primary_source":"","published":"2026-04-02T16:43:08.762Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-26961","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26961","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T17:58:12.149Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-26961","primary_source":"","published":"2026-04-02T16:42:16.766Z"},{"affected":"< 2.2.23; >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6","affected_versions_present":true,"cve_id":"CVE-2026-34230","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34230","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T18:19:00.388Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-34230","primary_source":"","published":"2026-04-02T16:41:21.095Z"},{"affected":"< 2.2.22; >= 3.0.0.beta1, < 3.1.20; >= 3.2.0, < 3.2.5","affected_versions_present":true,"cve_id":"CVE-2026-25500","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25500","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-18T19:42:35.101Z","patch_url":"https://github.com/rack/rack/commit/f2f225f297b99fbee3d9f51255d41f601fc40aff","primary_source":"","published":"2026-02-18T18:59:31.964Z"},{"affected":"< 2.2.22; >= 3.0.0.beta1, < 3.1.20; >= 3.2.0, < 3.2.5","affected_versions_present":true,"cve_id":"CVE-2026-22860","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22860","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:18:57.147Z","patch_url":"https://github.com/rack/rack/commit/75c5745c286637a8f049a33790c71237762069e7","primary_source":"","published":"2026-02-18T18:45:02.095Z"},{"affected":"< 2.2.20; >= 3.0, < 3.1.18; >= 3.2, < 3.2.3","affected_versions_present":true,"cve_id":"CVE-2025-61919","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61919","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-10-10T20:48:20.240Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-61919","primary_source":"","published":"2025-10-10T19:22:42.454Z"},{"affected":"< 2.2.20; >= 3.0, < 3.1.18; >= 3.2, < 3.2.3","affected_versions_present":true,"cve_id":"CVE-2025-61780","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61780","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-10T20:35:26.618Z","patch_url":"https://github.com/rack/rack/commit/57277b7741581fa827472c5c666f6e6a33abd784","primary_source":"","published":"2025-10-10T16:53:57.606Z"},{"affected":"< 2.2.19; >= 3.1, < 3.1.17; >= 3.2, < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2025-61772","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61772","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-10-07T17:51:26.246Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-61772","primary_source":"","published":"2025-10-07T15:02:09.895Z"},{"affected":"< 2.2.19; >= 3.1, < 3.1.17; >= 3.2, < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2025-61771","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61771","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-10-07T17:52:09.399Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-61771","primary_source":"","published":"2025-10-07T14:42:53.366Z"},{"affected":"< 2.2.19; >= 3.1, < 3.1.17; >= 3.2, < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2025-61770","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61770","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-10-07T15:43:06.827Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-61770","primary_source":"","published":"2025-10-07T14:30:04.552Z"},{"affected":"< 2.2.18","affected_versions_present":true,"cve_id":"CVE-2025-59830","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59830","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-09-25T16:16:15.255Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-59830","primary_source":"","published":"2025-09-25T14:37:06.967Z"},{"affected":">= 3.1.0, < 3.1.16","affected_versions_present":true,"cve_id":"CVE-2025-49007","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49007","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-05T14:11:25.234Z","patch_url":"https://github.com/rack/rack/commit/4795831a0a310c2d31102749e551b38faab6401f","primary_source":"","published":"2025-06-04T22:42:52.515Z"},{"affected":"< 2.2.14; >= 3.0, < 3.0.16; >= 3.1, < 3.1.14","affected_versions_present":true,"cve_id":"CVE-2025-46727","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-46727","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-08T14:01:06.865Z","patch_url":"https://github.com/rack/rack/commit/2bb5263b464b65ba4b648996a579dbd180d2b712","primary_source":"","published":"2025-05-07T23:07:40.563Z"},{"affected":"< 2.2.14","affected_versions_present":true,"cve_id":"CVE-2025-32441","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32441","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-08T14:02:25.736Z","patch_url":"https://github.com/rack/rack/commit/c48e52f7c57e99e1e1bf54c8760d4f082cd1c89d","primary_source":"","published":"2025-05-07T23:01:19.722Z"},{"affected":"< 2.2.13; >= 3.0, < 3.0.14; >= 3.1, < 3.1.12","affected_versions_present":true,"cve_id":"CVE-2025-27610","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27610","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:13:28.086Z","patch_url":"https://github.com/rack/rack/commit/50caab74fa01ee8f5dbdee7bb2782126d20c6583","primary_source":"","published":"2025-03-10T22:19:25.982Z"},{"affected":"< 2.2.12; >= 3.0, < 3.0.13; >= 3.1, < 3.1.11","affected_versions_present":true,"cve_id":"CVE-2025-27111","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27111","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:13:11.046Z","patch_url":"https://github.com/rack/rack/commit/803aa221e8302719715e224f4476e438f2531a53","primary_source":"","published":"2025-03-04T15:26:55.377Z"},{"affected":"< 2.2.11; >= 3.0, < 3.0.12; >= 3.1, < 3.1.10","affected_versions_present":true,"cve_id":"CVE-2025-25184","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25184","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:12:48.952Z","patch_url":"https://github.com/rack/rack/commit/074ae244430cda05c27ca91cda699709cfb3ad8e","primary_source":"","published":"2025-02-12T16:20:46.865Z"},{"affected":">= 3.1.0, < 3.1.5","affected_versions_present":true,"cve_id":"CVE-2024-39316","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-39316","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T04:19:20.629Z","patch_url":"https://github.com/rack/rack/commit/412c980450ca729ee37f90a2661f166a9665e058","primary_source":"","published":"2024-07-02T15:57:39.107Z"},{"affected":">= 3.0.0, < 3.0.9.1; >= 1.3.0, < 2.2.8.1","affected_versions_present":true,"cve_id":"CVE-2024-26141","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26141","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index","last_modified":"2025-02-13T17:41:04.867Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-26141","primary_source":"","published":"2024-02-28T23:28:10.503Z"},{"affected":">= 3.0.0, < 3.0.9.1; >= 0.4, < 2.2.8.1","affected_versions_present":true,"cve_id":"CVE-2024-25126","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-25126","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index","last_modified":"2025-02-13T17:40:47.635Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-25126","primary_source":"","published":"2024-02-28T23:28:07.073Z"},{"affected":">= 3.0.0, < 3.0.9.1; >= 2.2.0, < 2.2.8.1; >= 2.1.0, < 2.1.4.4; < 2.0.9.4","affected_versions_present":true,"cve_id":"CVE-2024-26146","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26146","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index","last_modified":"2025-02-13T17:41:07.669Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-26146","primary_source":"","published":"2024-02-28T23:28:01.158Z"},{"affected":"before 1.6.12 or 2.0.8","affected_versions_present":true,"cve_id":"CVE-2019-16782","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16782","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T01:24:48.031Z","patch_url":"https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38","primary_source":"","published":"2019-12-18T19:05:14.000Z"},{"affected":"2.0.6, 1.6.11","affected_versions_present":true,"cve_id":"CVE-2018-16471","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-16471","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T10:24:32.587Z","patch_url":"","primary_source":"","published":"2018-11-13T23:00:00.000Z"},{"affected":"2.0.6","affected_versions_present":true,"cve_id":"CVE-2018-16470","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-16470","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T10:24:32.612Z","patch_url":"","primary_source":"","published":"2018-11-13T23:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Rack"}}
