CVE-2026-34785 | Rack up to 2.2.22/3.1.20/3.2.5 Request Path /css Rack::Static partial string comparison (GHSA-h2jq-g4cq-5ppq / Nessus ID 305959)
A vulnerability described as problematic has been identified in Rack up to 2.2.22/3.1.20/3.2.5. This vulnerability affects the function Rack::Static of the file /css of the component Request Path Handler. Executing a manipulation can lead to partial string comparison.
This vulnerability is registered as CVE-2026-34785. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.