ruby-rack - security update

Published September 10, 2026 DSA-6492-1

Debian published a security update for ruby-rack. The advisory references CVE-2026-26961, CVE-2026-26962, CVE-2026-32762, CVE-2026-34230, CVE-2026-34763, CVE-2026-34785, CVE-2026-34786, CVE-2026-34826.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 3.1.20-0+deb13u2
Affects
ruby-rack
Exploited
Not confirmedNo confirmation recorded

How it works

The Debian tracker links this update to CVE-2026-26961, CVE-2026-26962, CVE-2026-32762, CVE-2026-34230, CVE-2026-34763, CVE-2026-34785, CVE-2026-34786, CVE-2026-34826.

What to do

Run apt policy ruby-rack and check whether the installed package is older than the fixed Debian security version.

Install the Debian security update for ruby-rack.

Technical details

Debian published a security update for ruby-rack. The advisory references CVE-2026-26961, CVE-2026-26962, CVE-2026-32762, CVE-2026-34230, CVE-2026-34763, CVE-2026-34785, CVE-2026-34786, CVE-2026-34826. Fixed versions: trixie: ruby-rack 3.1.20-0+deb13u2.