CVE-2026-26962 | Rack up to 3.2.5 HTTP Response Header Rack::Multipart crlf injection (Nessus ID 305960)
A vulnerability classified as problematic was found in Rack up to 3.2.5. This affects the function Rack::Multipart of the component HTTP Response Header Handler. Such manipulation leads to crlf injection.
This vulnerability is documented as CVE-2026-26962. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.