CVE-2026-39324 | rack rack-session up to 2.1.1 Rack::Session improper authentication (GHSA-33qg-7wpp-89cq)
A vulnerability, which was classified as critical, was found in rack rack-session up to 2.1.1. Affected is the function Rack::Session. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2026-39324. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.