UbuntuUpdates.org

Package "ruby-rack-session"

Name: ruby-rack-session

Description:

Session management implementation for Rack

Latest version: 2.1.1-0.1ubuntu0.26.04.1
Release: resolute (26.04)
Level: security
Repository: main
Homepage: https://github.com/rack/rack-session

Links


Download "ruby-rack-session"


Other versions of "ruby-rack-session" in Resolute

Repository Area Version
base main 2.1.1-0.1build1
updates main 2.1.1-0.1ubuntu0.26.04.1

Changelog

Version: 2.1.1-0.1ubuntu0.26.04.1 2026-04-28 15:08:04 UTC

  ruby-rack-session (2.1.1-0.1ubuntu0.26.04.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Acceptance of unencrypted cookie when decryption fails.
    - debian/patches/CVE-2026-39324.patch: Add encryptors.empty? check in
      lib/rack/session/cookie.rb. Add tests in test/spec_session_cookie.rb.
    - CVE-2026-39324

 -- Hlib Korzhynskyy <email address hidden> Mon, 27 Apr 2026 15:16:20 -0230

CVE-2026-39324 Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu



About   -   Send Feedback to @ubuntu_updates