{"cves":[{"id":"CVE-2026-26962","published":"2026-04-02T18:16:00","updated_at":"2026-04-23T11:58:01.242092+00:00","description":"\nRack is a modular Ruby web server interface. From version 3.2.0 to before\nversion 3.2.6, Rack::Multipart::Parser unfolds folded multipart part\nheaders incorrectly. When a multipart header contains an obs-fold sequence,\nRack preserves the embedded CRLF in parsed parameter values such as\nfilename or name instead of removing the folded line break during\nunfolding. As a result, applications that later reuse those parsed values\nin HTTP response headers may be vulnerable to downstream header injection\nor response splitting. This issue has been patched in version 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-26962","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/d50c4d3dab62fa80b2a276271d0d4fb338cfa7df"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [changes too intrusive]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-35388","published":"2026-04-02T17:16:00","updated_at":"2026-04-29T13:32:30.510708+00:00","description":"\nOpenSSH before 10.3 omits connection multiplexing confirmation for\nproxy-mode multiplexing sessions.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":2.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":2.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-35388","https://ubuntu.com/security/notices/USN-8222-1"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/c805b97b67c774e0bf922ffb29dfbcda9d7b5add"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.16","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:10.0p1-5ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8222-1"],"notices":[{"id":"USN-8222-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-29T12:10:19.609558","description":"Christos Papakonstantinou discovered that the OpenSSH scp tool incorrectly\nhandled the legacy scp protocol (-O) option. This could result in certain\nfiles being installed setuid or setgid, contrary to expectations.\n(CVE-2026-35385)\n\nFlorian Kohnhäuser discovered that OpenSSH incorrectly handled shell\nmetacharacters in usernames within a command line. When untrusted usernames\nand non-default configurations using % in ssh_config are being used, an\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-35386)\n\nChristos Papakonstantinou discovered that OpenSSH incorrectly handled\nparsing the PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms\noptions. This could result in unintended ECDSA algorithms being used,\ncontrary to expectations. (CVE-2026-35387)\n\nMichalis Vasileiadis discovered that OpenSSH incorrectly handled\nproxy-mode multiplexing sessions. This could result in no confirmation\nbeing asked, contrary to expectations. (CVE-2026-35388)\n\nVladimir Tokarev discovered that OpenSSH incorrectly handled certificates\nwith the principal name containing a comma character when using user-trusted\nCA keys in authorized_keys and an authorized_keys principals=\"\" option\nthat lists more than one principal. This could result in inappropriate\nprincipal matching, contrary to expectations. (CVE-2026-35414)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.15","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"}],"questing":[{"name":"openssh","version":"1:10.0p1-5ubuntu5.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.2","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-35414","CVE-2026-35387","CVE-2026-35386","CVE-2026-35388","CVE-2026-35385"]}]},{"id":"CVE-2026-35387","published":"2026-04-02T17:16:00","updated_at":"2026-04-29T13:32:30.510708+00:00","description":"\nOpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any\nECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms\nis misinterpreted to mean all ECDSA algorithms.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-35387","https://www.openssh.org/releasenotes.html#10.3p1","https://ubuntu.com/security/notices/USN-8222-1"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/fd1c7e131f331942d20f42f31e79912d570081fa"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.16","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:10.0p1-5ubuntu5.4","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8222-1"],"notices":[{"id":"USN-8222-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-29T12:10:19.609558","description":"Christos Papakonstantinou discovered that the OpenSSH scp tool incorrectly\nhandled the legacy scp protocol (-O) option. This could result in certain\nfiles being installed setuid or setgid, contrary to expectations.\n(CVE-2026-35385)\n\nFlorian Kohnhäuser discovered that OpenSSH incorrectly handled shell\nmetacharacters in usernames within a command line. When untrusted usernames\nand non-default configurations using % in ssh_config are being used, an\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-35386)\n\nChristos Papakonstantinou discovered that OpenSSH incorrectly handled\nparsing the PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms\noptions. This could result in unintended ECDSA algorithms being used,\ncontrary to expectations. (CVE-2026-35387)\n\nMichalis Vasileiadis discovered that OpenSSH incorrectly handled\nproxy-mode multiplexing sessions. This could result in no confirmation\nbeing asked, contrary to expectations. (CVE-2026-35388)\n\nVladimir Tokarev discovered that OpenSSH incorrectly handled certificates\nwith the principal name containing a comma character when using user-trusted\nCA keys in authorized_keys and an authorized_keys principals=\"\" option\nthat lists more than one principal. This could result in inappropriate\nprincipal matching, contrary to expectations. (CVE-2026-35414)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.15","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"}],"questing":[{"name":"openssh","version":"1:10.0p1-5ubuntu5.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.2","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-35414","CVE-2026-35387","CVE-2026-35386","CVE-2026-35388","CVE-2026-35385"]}]},{"id":"CVE-2026-35386","published":"2026-04-02T17:16:00","updated_at":"2026-04-29T13:32:30.510708+00:00","description":"\nIn OpenSSH before 10.3, command execution can occur via shell\nmetacharacters in a username within a command line. This requires a\nscenario where the username on the command line is untrusted, and also\nrequires a non-default configurations of % in ssh_config.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":3.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.6,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-35386","https://www.openssh.org/releasenotes.html#10.3p1","https://ubuntu.com/security/notices/USN-8222-1"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/76685c9b09a66435cd2ad8373246adf1c53976d3"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.16","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:10.0p1-5ubuntu5.4","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8222-1"],"notices":[{"id":"USN-8222-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-29T12:10:19.609558","description":"Christos Papakonstantinou discovered that the OpenSSH scp tool incorrectly\nhandled the legacy scp protocol (-O) option. This could result in certain\nfiles being installed setuid or setgid, contrary to expectations.\n(CVE-2026-35385)\n\nFlorian Kohnhäuser discovered that OpenSSH incorrectly handled shell\nmetacharacters in usernames within a command line. When untrusted usernames\nand non-default configurations using % in ssh_config are being used, an\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-35386)\n\nChristos Papakonstantinou discovered that OpenSSH incorrectly handled\nparsing the PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms\noptions. This could result in unintended ECDSA algorithms being used,\ncontrary to expectations. (CVE-2026-35387)\n\nMichalis Vasileiadis discovered that OpenSSH incorrectly handled\nproxy-mode multiplexing sessions. This could result in no confirmation\nbeing asked, contrary to expectations. (CVE-2026-35388)\n\nVladimir Tokarev discovered that OpenSSH incorrectly handled certificates\nwith the principal name containing a comma character when using user-trusted\nCA keys in authorized_keys and an authorized_keys principals=\"\" option\nthat lists more than one principal. This could result in inappropriate\nprincipal matching, contrary to expectations. (CVE-2026-35414)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.15","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"}],"questing":[{"name":"openssh","version":"1:10.0p1-5ubuntu5.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.2","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-35414","CVE-2026-35387","CVE-2026-35386","CVE-2026-35388","CVE-2026-35385"]}]},{"id":"CVE-2026-35385","published":"2026-04-02T17:16:00","updated_at":"2026-09-16T16:27:12.967539+00:00","description":"\nIn OpenSSH before 10.3, a file downloaded by scp may be installed setuid or\nsetgid, an outcome contrary to some users' expectations, if the download is\nperformed as root with -O (legacy scp protocol) and without -p (preserve\nmode).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-35385","https://ubuntu.com/security/notices/USN-8222-1","https://ubuntu.com/security/notices/USN-8514-1","https://ubuntu.com/security/notices/USN-8514-2"],"bugs":[""],"patches":{"openssh":["upstream: https://github.com/openssh/openssh-portable/commit/487e8ac146f7d6616f65c125d5edb210519b833a"],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"bionic","status":"released","description":"1:7.6p1-4ubuntu0.7+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1:8.2p1-4ubuntu0.13+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1:6.6p1-2ubuntu2.13+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1:7.2p2-4ubuntu2.10+esm8","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"resolute","status":"released","description":"1:10.2p1-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.16","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:10.0p1-5ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8222-1","USN-8514-1","USN-8514-2"],"notices":[{"id":"USN-8222-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-29T12:10:19.609558","description":"Christos Papakonstantinou discovered that the OpenSSH scp tool incorrectly\nhandled the legacy scp protocol (-O) option. This could result in certain\nfiles being installed setuid or setgid, contrary to expectations.\n(CVE-2026-35385)\n\nFlorian Kohnhäuser discovered that OpenSSH incorrectly handled shell\nmetacharacters in usernames within a command line. When untrusted usernames\nand non-default configurations using % in ssh_config are being used, an\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-35386)\n\nChristos Papakonstantinou discovered that OpenSSH incorrectly handled\nparsing the PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms\noptions. This could result in unintended ECDSA algorithms being used,\ncontrary to expectations. (CVE-2026-35387)\n\nMichalis Vasileiadis discovered that OpenSSH incorrectly handled\nproxy-mode multiplexing sessions. This could result in no confirmation\nbeing asked, contrary to expectations. (CVE-2026-35388)\n\nVladimir Tokarev discovered that OpenSSH incorrectly handled certificates\nwith the principal name containing a comma character when using user-trusted\nCA keys in authorized_keys and an authorized_keys principals=\"\" option\nthat lists more than one principal. This could result in inappropriate\nprincipal matching, contrary to expectations. (CVE-2026-35414)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.15","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.15","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.16","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.16","pocket":"security"}],"questing":[{"name":"openssh","version":"1:10.0p1-5ubuntu5.4","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"openssh-tests","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.0p1-5ubuntu5.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.4","pocket":"security"}],"resolute":[{"name":"openssh","version":"1:10.2p1-2ubuntu3.2","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"openssh-tests","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.2p1-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-35414","CVE-2026-35387","CVE-2026-35386","CVE-2026-35388","CVE-2026-35385"]},{"id":"USN-8514-1","title":"OpenSSH vulnerability","summary":"OpenSSH could be made to overwrite files as the administrator.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-06T14:32:58.279392","description":"It was discovered that OpenSSH incorrectly handled file permissions when\ndownloading files as root using the legacy scp protocol without the\npreserve-mode option. An attacker could use this to install setuid or setgid\nfiles on a system, possibly leading to privilege escalation.","is_hidden":false,"release_packages":{"xenial":[{"name":"openssh","version":"1:7.2p2-4ubuntu2.10+esm8","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssh-client-ssh1","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssh-server","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssh-sftp-server","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ssh","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ssh-askpass-gnome","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ssh-krb5","version":"1:7.2p2-4ubuntu2.10+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-35385"]},{"id":"USN-8514-2","title":"OpenSSH vulnerability","summary":"OpenSSH could be made to overwrite files as the administrator.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-16T08:46:47.485779","description":"USN-8514-1 fixed a vulnerability in OpenSSH. This update provides\nthe corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that OpenSSH incorrectly handled file permissions when\n downloading files as root using the legacy scp protocol without the\n preserve-mode option. An attacker could use this to install setuid or setgid\n files on a system, possibly leading to privilege escalation.","is_hidden":false,"release_packages":{"bionic":[{"name":"openssh","version":"1:7.6p1-4ubuntu0.7+esm5","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:7.6p1-4ubuntu0.7+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-server","version":"1:7.6p1-4ubuntu0.7+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-sftp-server","version":"1:7.6p1-4ubuntu0.7+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"ssh","version":"1:7.6p1-4ubuntu0.7+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"ssh-askpass-gnome","version":"1:7.6p1-4ubuntu0.7+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssh","version":"1:8.2p1-4ubuntu0.13+esm2","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.2p1-4ubuntu0.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-server","version":"1:8.2p1-4ubuntu0.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-sftp-server","version":"1:8.2p1-4ubuntu0.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-tests","version":"1:8.2p1-4ubuntu0.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"ssh","version":"1:8.2p1-4ubuntu0.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"ssh-askpass-gnome","version":"1:8.2p1-4ubuntu0.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssh","version":"1:6.6p1-2ubuntu2.13+esm3","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:6.6p1-2ubuntu2.13+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssh-server","version":"1:6.6p1-2ubuntu2.13+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssh-sftp-server","version":"1:6.6p1-2ubuntu2.13+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ssh","version":"1:6.6p1-2ubuntu2.13+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ssh-askpass-gnome","version":"1:6.6p1-2ubuntu2.13+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ssh-krb5","version":"1:6.6p1-2ubuntu2.13+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-35385"]}]},{"id":"CVE-2026-34877","published":"2026-04-02T17:16:00","updated_at":"2026-04-08T18:34:16.332977+00:00","description":"\nAn issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed\nTLS 4.0.0. Insufficient protection of serialized SSL context or session\nstructures allows an attacker who can modify the serialized structures to\ninduce memory corruption, leading to arbitrary code execution. This is\ncaused by Incorrect Use of Privileged APIs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34877","https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-serialized-data/"],"bugs":[""],"patches":{"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-34831","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T11:49:17.210793+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header\nusing String#size instead of String#bytesize. When the response body\ncontains multibyte UTF-8 characters, the declared Content-Length is smaller\nthan the number of bytes actually sent on the wire. Because Rack::Files\nreflects the requested path in 404 responses, an attacker can trigger this\nmismatch by requesting a non-existent path containing percent-encoded UTF-8\ncharacters. This results in incorrect HTTP response framing and may cause\nresponse desynchronization in deployments that rely on the incorrect\nContent-Length value. This issue has been patched in versions 2.2.23,\n3.1.21, and 3.2.6.","ubuntu_description":"","notes":[{"author":"kkernick","note":"2.0.7 and below enforce ASCII encoding. Any attempt\nto pass Unicode raises a LintError."}],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34831","https://github.com/rack/rack/security/advisories/GHSA-q2ww-5357-x388","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/10ecd9a8a02083297f925f0d9255a93ebde4c0da"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34830","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T11:32:28.318633+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of\nthe X-Accel-Mapping request header directly into a regular expression when\nrewriting file paths for X-Accel-Redirect. Because the header value is not\nescaped, an attacker who can supply X-Accel-Mapping to the backend can\ninject regex metacharacters and control the generated X-Accel-Redirect\nresponse header. In deployments using Rack::Sendfile with x-accel-redirect,\nthis can allow an attacker to cause nginx to serve unintended files from\nconfigured internal locations. This issue has been patched in versions\n2.2.23, 3.1.21, and 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34830","https://github.com/rack/rack/security/advisories/GHSA-qv7j-4883-hwh7","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/a57bc140247f904dc1e3302badedcb73645072c7"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.4-3ubuntu0.2+esm10","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34829","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T11:19:53.855306+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a\nBoundedIO when CONTENT_LENGTH is present. When a multipart/form-data\nrequest is sent without a Content-Length header, such as with HTTP chunked\ntransfer encoding, multipart parsing continues until end-of-stream with no\ntotal size limit. For file parts, the uploaded body is written directly to\na temporary file on disk rather than being constrained by the buffered\nin-memory upload limit. An unauthenticated attacker can therefore stream an\narbitrarily large multipart file upload and consume unbounded disk space.\nThis results in a denial of service condition for Rack applications that\naccept multipart form data. This issue has been patched in versions 2.2.23,\n3.1.21, and 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34829","https://github.com/rack/rack/security/advisories/GHSA-8vqr-qjwx-82mw","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/b3e5945c648c5a5b6982e5072b26e51990991229"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [changes too intrusive]","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34826","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T10:43:50.157766+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header\nwithout limiting the number of individual byte ranges. Although the\nexisting fix for CVE-2024-26141 rejects ranges whose total byte coverage\nexceeds the file size, it does not restrict the count of ranges. An\nattacker can supply many small overlapping ranges such as 0-0,0-0,0-0,...\nto trigger disproportionate CPU, memory, I/O, and bandwidth consumption per\nrequest. This results in a denial of service condition in Rack file-serving\npaths that process multipart byte range responses. This issue has been\npatched in versions 2.2.23, 3.1.21, and 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34826","https://github.com/rack/rack/security/advisories/GHSA-x8cg-fq8g-mxfx","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/9138756fb0bcfb500abbb0b8ed90bc24911ff6a3"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.4-3ubuntu0.2+esm10","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34786","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T11:45:25.729075+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several\nheader_rules types against the raw URL-encoded PATH_INFO, while the\nunderlying file-serving path is decoded before the file is served. As a\nresult, a request for a URL-encoded variant of a static path can serve the\nsame file without the headers that header_rules were intended to apply. In\ndeployments that rely on Rack::Static to attach security-relevant response\nheaders to static content, this can allow an attacker to bypass those\nheaders by requesting an encoded form of the path. This issue has been\npatched in versions 2.2.23, 3.1.21, and 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34786","https://github.com/rack/rack/security/advisories/GHSA-q4qf-9j86-f5mh","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/d6af0639e25ec6f3cc12bf64baa4b991be0cbfa1"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [changes too intrusive]","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34785","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T10:59:12.383911+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Static determines whether a request should be\nserved as a static file using a simple string prefix check. When configured\nwith URL prefixes such as \"/css\", it matches any request path that begins\nwith that string, including unrelated paths such as \"/css-config.env\" or\n\"/css-backup.sql\". As a result, files under the static root whose names\nmerely share the configured prefix may be served unintentionally, leading\nto information disclosure. This issue has been patched in versions 2.2.23,\n3.1.21, and 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34785","https://github.com/rack/rack/security/advisories/GHSA-h2jq-g4cq-5ppq","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/7a8f32696609b88e2c4c1f09d473a1d2d837ed4b"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.2-3+deb8u3ubuntu1~esm11","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.6.4-3ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34763","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T10:53:39.676935+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path\ndirectly into a regular expression when deriving the displayed directory\npath. If root contains regex metacharacters such as +, *, or ., the prefix\nstripping can fail and the generated directory listing may expose the full\nfilesystem path in the HTML output. This issue has been patched in versions\n2.2.23, 3.1.21, and 3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34763","https://github.com/rack/rack/security/advisories/GHSA-7mqq-6cf9-v2qp","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/459ea1f5a58455409e377d60eeb3432ff3100e15"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.2-3+deb8u3ubuntu1~esm11","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.6.4-3ubuntu0.2+esm10","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-34230","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T11:32:28.318633+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes\nAccept-Encoding values with quadratic time complexity when the header\ncontains many wildcard (*) entries. Because this method is used by\nRack::Deflater to choose a response encoding, an unauthenticated attacker\ncan send a single request with a crafted Accept-Encoding header and cause\ndisproportionate CPU consumption on the compression middleware path. This\nresults in a denial of service condition for applications using\nRack::Deflater. This issue has been patched in versions 2.2.23, 3.1.21, and\n3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34230","https://github.com/rack/rack/security/advisories/GHSA-v569-hp3g-36wr","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/8bf0c2eb5936eb79207f3a0be63196e7726bcb0a"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.2-3+deb8u3ubuntu1~esm11","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.6.4-3ubuntu0.2+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2026-26961","published":"2026-04-02T17:16:00","updated_at":"2026-04-23T11:31:34.882833+00:00","description":"\nRack is a modular Ruby web server interface. Prior to versions 2.2.23,\n3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter\nfrom multipart/form-data using a greedy regular expression. When a\nContent-Type header contains multiple boundary parameters, Rack selects the\nlast one rather than the first. In deployments where an upstream proxy,\nWAF, or intermediary interprets the first boundary parameter, this mismatch\ncan allow an attacker to smuggle multipart content past upstream inspection\nand have Rack parse a different body structure than the intermediary\nvalidated. This issue has been patched in versions 2.2.23, 3.1.21, and\n3.2.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-26961","https://github.com/rack/rack/security/advisories/GHSA-vgpv-f759-9wx3","https://ubuntu.com/security/notices/USN-8182-1"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/1c0b723dbb0a01ac509ce971e0bd859f405a8e61"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1+esm10","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.1.4-5ubuntu1.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"2.2.7-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.16-0.1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.2.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [changes too intrusive]","component":null,"pocket":"security"}]}],"notices_ids":["USN-8182-1"],"notices":[{"id":"USN-8182-1","title":"Rack vulnerabilities","summary":"Several security issues were fixed in Rack.","instructions":"After a standard system update you need to restart any applications using\nRack to make all the necessary changes.","references":[],"published":"2026-04-17T00:23:44.260898","description":"Andrew Lacambra discovered that Rack did not properly parse certain regular\nexpressions. An attacker could possibly use this issue to bypass network\nsecurity filters. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-26961)\n\nWilliam T. Nelson discovered that Rack did not handle multipart headers\ncorrectly. An attacker could possibly use this issue to cause downstream\nparsing issues or a denial of service. This issue only affected Ubuntu\n25.10. (CVE-2026-26962)\n\nIt was discovered that Rack did not handle the Forwarded header correctly.\nAn attacker could possibly use this issue to manipulate header values. This\nissue only affected Ubuntu 25.10. (CVE-2026-32762)\n\nIt was discovered that Rack could consume excessive CPU when handling\ncertain Accept-Encoding values. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-34230)\n\nHaruki Oyama discovered that certain configurations of Rack could\nerroneously fail to derive the displayed directory path, and expose the\nfull filesystem path. An attacker could possibly use this issue to disclose\ndeployment details such as layout and usernames. (CVE-2026-34763)\n\nIt was discovered that Rack did not properly handle static file paths. An\nattacker could possibly use this issue to exfiltrate unintentionally served\ndata. (CVE-2026-34785)\n\nHaruki Oyama discovered that Rack did not apply header rules to certain\nrequests for URL-encoded static paths. An attacker could possibly use this\nissue to bypass security-relevant response headers. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\nLTS, and Ubuntu 25.10. (CVE-2026-34786)\n\nIt was discovered that Rack did not limit the number of ranges requested in\nthe Range header. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34826)\n\nIt was discovered that Rack could consume excessive CPU when parsing\ncertain multipart parameters. An attacker could possibly use this to cause\na denial of service. This issue only affected Ubuntu 25.10.\n(CVE-2026-34827)\n\nIt was discovered that Rack could consume unbounded disk space when\nhandling requests without a Content-Length header. An attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34829)\n\nMehtab Zafar discovered that Rack directly interpreted the X-Accel-Mapping\nheader as a regular expression without escaping. An attacker could possibly\nuse this issue to exfiltrate arbitrary files from internal locations. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-34830)\n\nIt was discovered that Rack did not properly handle messages with Unicode.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.10. (CVE-2026-34831)\n\nIt was discovered that Rack did not properly parse the Host header. An\nattacker could possibly use this issue to bypass security filters or poison\ngenerated links. This issue only affected Ubuntu 25.10. (CVE-2026-34835)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.4-5ubuntu1.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.2.7-1ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7","pocket":"security"}],"questing":[{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"3.1.16-0.1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/3.1.16-0.1ubuntu0.3","pocket":"security"}],"trusty":[{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","description":"modular Ruby webserver interface","is_source":true},{"name":"librack-ruby","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.8","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"librack-ruby1.9.1","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"ruby-rack","version":"1.5.2-3+deb8u3ubuntu1~esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-26962","CVE-2026-34827","CVE-2026-26961","CVE-2026-34835","CVE-2026-32762","CVE-2026-34826","CVE-2026-34786","CVE-2026-34785","CVE-2026-34829","CVE-2026-34763","CVE-2026-34831","CVE-2026-34230","CVE-2026-34830"]}]},{"id":"CVE-2025-65114","published":"2026-04-02T17:16:00","updated_at":"2026-04-08T18:32:33.123369+00:00","description":"\nApache Traffic Server allows request smuggling if chunked messages are\nmalformed.\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from\n10.0.0 through 10.1.1.\nUsers are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-65114"],"bugs":[""],"patches":{"trafficserver":[]},"tags":{},"packages":[{"name":"trafficserver","source":"https://ubuntu.com/security/cve?package=trafficserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trafficserver","debian":"https://tracker.debian.org/pkg/trafficserver","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-58136","published":"2026-04-02T17:16:00","updated_at":"2026-04-08T18:35:12.671832+00:00","description":"\nA bug in POST request handling causes a crash under a certain condition.\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from\n9.0.0 through 9.2.12.\nUsers are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the\nissue.\nA workaround for older versions is to\nset proxy.config.http.request_buffer_enabled to 0 (the default value is 0).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-58136"],"bugs":[""],"patches":{"trafficserver":[]},"tags":{},"packages":[{"name":"trafficserver","source":"https://ubuntu.com/security/cve?package=trafficserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trafficserver","debian":"https://tracker.debian.org/pkg/trafficserver","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-34876","published":"2026-04-02T16:16:00","updated_at":"2026-04-08T18:36:35.217388+00:00","description":"\nAn issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read\nvulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to\nobtain adjacent CCM context data via invocation of the multipart CCM API\nwith an oversized tag_len parameter. This is caused by missing validation\nof the tag_len parameter against the size of the internal 16-byte\nauthentication buffer. The issue affects the public multipart CCM API in\nMbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by\napplications. In Mbed TLS 4.x versions prior to the fix, the same missing\nvalidation exists in the internal implementation; however, the function is\nnot exposed as part of the public API. Exploitation requires\napplication-level invocation of the multipart CCM API.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34876","https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ccm-finish-boundary-check/"],"bugs":[""],"patches":{"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-33691","published":"2026-04-02T16:16:00","updated_at":"2026-04-08T18:36:17.568988+00:00","description":"\nThe OWASP core rule set (CRS) is a set of generic attack detection rules\nfor use with compatible web application firewalls. Prior to versions 3.3.9\nand 4.25.0, a bypass was identified in OWASP CRS that allows uploading\nfiles with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting\nwhitespace padding in the filename (e.g. photo. php or shell.jsp ). The\naffected rules do not normalize whitespace before evaluating the file\nextension regex, so the dot-extension check fails to match. This issue has\nbeen patched in versions 3.3.9 and 4.25.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-33691","https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w"],"bugs":[""],"patches":{"modsecurity-crs":[]},"tags":{},"packages":[{"name":"modsecurity-crs","source":"https://ubuntu.com/security/cve?package=modsecurity-crs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=modsecurity-crs","debian":"https://tracker.debian.org/pkg/modsecurity-crs","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3.9-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5342","published":"2026-04-02T15:16:00","updated_at":"2026-07-09T15:23:46.273573+00:00","description":"\nA flaw has been found in LibRaw up to 0.22.0. This affects the function\nLibRaw::nikon_load_padded_packed_raw of the file\nsrc/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a\nmanipulation of the argument load_flags/raw_width can lead to out-of-bounds\nread. It is possible to launch the attack remotely. The exploit has been\npublished and may be used. Upgrading to version 0.22.1 mitigates this\nissue. This patch is called b8397cd45657b84e88bd1202528d1764265f185c. It is\nadvisable to upgrade the affected component.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5342","https://ubuntu.com/security/notices/USN-8522-1"],"bugs":["https://github.com/LibRaw/LibRaw/issues/795"],"patches":{"libraw":["upstream: https://github.com/LibRaw/LibRaw/commit/b8397cd45657b84e88bd1202528d1764265f185c","upstream: https://github.com/LibRaw/LibRaw/commit/2468614a9cbcab6b75ca279ab60cac62156f7aeb"],"ufraw":[],"darktable":[],"exactimage":[],"dcraw":[],"rawtherapee":[],"kodi":[],"digikam":[]},"tags":{},"packages":[{"name":"libraw","source":"https://ubuntu.com/security/cve?package=libraw","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libraw","debian":"https://tracker.debian.org/pkg/libraw","statuses":[{"release_codename":"jammy","status":"released","description":"0.20.2-2ubuntu2.22.04.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.21.2-2.1ubuntu0.24.04.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.21.5b-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"ufraw","source":"https://ubuntu.com/security/cve?package=ufraw","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ufraw","debian":"https://tracker.debian.org/pkg/ufraw","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"darktable","source":"https://ubuntu.com/security/cve?package=darktable","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=darktable","debian":"https://tracker.debian.org/pkg/darktable","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"exactimage","source":"https://ubuntu.com/security/cve?package=exactimage","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exactimage","debian":"https://tracker.debian.org/pkg/exactimage","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dcraw","source":"https://ubuntu.com/security/cve?package=dcraw","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dcraw","debian":"https://tracker.debian.org/pkg/dcraw","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"rawtherapee","source":"https://ubuntu.com/security/cve?package=rawtherapee","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rawtherapee","debian":"https://tracker.debian.org/pkg/rawtherapee","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kodi","source":"https://ubuntu.com/security/cve?package=kodi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi","debian":"https://tracker.debian.org/pkg/kodi","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"digikam","source":"https://ubuntu.com/security/cve?package=digikam","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=digikam","debian":"https://tracker.debian.org/pkg/digikam","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8522-1"],"notices":[{"id":"USN-8522-1","title":"LibRaw vulnerabilities","summary":"Several security issues were fixed in LibRaw.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-09T12:45:50.212717","description":"It was discovered that LibRaw incorrectly handled certain Nikon RAW image\nfiles. An attacker could possibly use this issue to cause LibRaw to crash,\nresulting in a denial of service. (CVE-2026-5342)\n\nIt was discovered that LibRaw had an integer overflow in its DNG image\nloader. An attacker could possibly use this issue to cause LibRaw to\ncrash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-20884)\n\nIt was discovered that LibRaw incorrectly handled certain X3F thumbnail\ndata. An attacker could possibly use this issue to cause LibRaw to crash,\nresulting in a denial of service, or execute arbitrary code.\n(CVE-2026-20889)\n\nIt was discovered that LibRaw had a heap-based buffer overflow in its\nlossless JPEG image loader. An attacker could possibly use this issue to\ncause LibRaw to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-21413)\n\nIt was discovered that LibRaw had an integer overflow in its uncompressed\nfloating-point DNG image loader. An attacker could possibly use this issue\nto cause LibRaw to crash, resulting in a denial of service, or execute\narbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 25.04.\n(CVE-2026-24450)\n\nIt was discovered that LibRaw had a heap-based buffer overflow in its X3F\nHuffman decoder. An attacker could possibly use this issue to cause LibRaw\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-24660)","is_hidden":false,"release_packages":{"jammy":[{"name":"libraw","version":"0.20.2-2ubuntu2.22.04.3","description":"raw image decoder library","is_source":true},{"name":"libraw-bin","version":"0.20.2-2ubuntu2.22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.20.2-2ubuntu2.22.04.3","pocket":"security"},{"name":"libraw-dev","version":"0.20.2-2ubuntu2.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.20.2-2ubuntu2.22.04.3","pocket":"security"},{"name":"libraw-doc","version":"0.20.2-2ubuntu2.22.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.20.2-2ubuntu2.22.04.3","pocket":"security"},{"name":"libraw20","version":"0.20.2-2ubuntu2.22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.20.2-2ubuntu2.22.04.3","pocket":"security"}],"noble":[{"name":"libraw","version":"0.21.2-2.1ubuntu0.24.04.2","description":"raw image decoder library","is_source":true},{"name":"libraw-bin","version":"0.21.2-2.1ubuntu0.24.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.2-2.1ubuntu0.24.04.2","pocket":"security"},{"name":"libraw-dev","version":"0.21.2-2.1ubuntu0.24.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.2-2.1ubuntu0.24.04.2","pocket":"security"},{"name":"libraw-doc","version":"0.21.2-2.1ubuntu0.24.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.2-2.1ubuntu0.24.04.2","pocket":"security"},{"name":"libraw23t64","version":"0.21.2-2.1ubuntu0.24.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.2-2.1ubuntu0.24.04.2","pocket":"security"}],"resolute":[{"name":"libraw","version":"0.21.5b-1ubuntu1.1","description":"raw image decoder library","is_source":true},{"name":"libraw-bin","version":"0.21.5b-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.5b-1ubuntu1.1","pocket":"security"},{"name":"libraw-dev","version":"0.21.5b-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.5b-1ubuntu1.1","pocket":"security"},{"name":"libraw-doc","version":"0.21.5b-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.5b-1ubuntu1.1","pocket":"security"},{"name":"libraw23t64","version":"0.21.5b-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.21.5b-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-24450","CVE-2026-20884","CVE-2026-5342","CVE-2026-24660","CVE-2026-20889","CVE-2026-21413"]}]}],"offset":14060,"limit":20,"total_results":79316}