CVE & CISA-KEV Catalog

CVE-2024-26146

MEDIUMEPSS 79th pctl
5.3
CVSS v3
NVD

Description

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.

How to fix

Remediation Available
ruby-rackDebian
Fixed in:2.1.4-3+deb11u2CVE-2024-26146
Fixed in:2.2.6.4-1+deb12u1CVE-2024-26146
Fixed in:2.2.7-1.1CVE-2024-26146
Fixed in:2.2.7-1.1CVE-2024-26146
foremanRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foremanRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-cliRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-cliRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-debugRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-debugRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-dynflow-sidekiqRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-dynflow-sidekiqRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-ec2Rocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-ec2Red Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-fapolicydRocky
Fixed in:0:1.0.1-3.el8satRHSA-2024:10806
Fixed in:0:1.0.1-3.el8satRHSA-2024:10806
foreman-fapolicydRed Hat / RHEL
Fixed in:0:1.0.1-3.el8satRHSA-2024:10806
Fixed in:0:1.0.1-3.el8satRHSA-2024:10806
foreman-installerRed Hat / RHEL
Fixed in:1:3.9.3.7-1.el8satRHSA-2024:10806
Fixed in:1:3.9.3.7-1.el8satRHSA-2024:10806
foreman-installerRocky
Fixed in:1:3.9.3.7-1.el8satRHSA-2024:10806
Fixed in:1:3.9.3.7-1.el8satRHSA-2024:10806
foreman-installer-katelloRocky
Fixed in:1:3.9.3.7-1.el8satRHSA-2024:10806
foreman-installer-katelloRed Hat / RHEL
Fixed in:1:3.9.3.7-1.el8satRHSA-2024:10806
foreman-journaldRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-journaldRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-libvirtRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-libvirtRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-openstackRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-openstackRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-ovirtRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-ovirtRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-pcpRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-pcpRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-postgresqlRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-postgresqlRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-proxy-fapolicydRocky
Fixed in:0:1.0.1-3.el8satRHSA-2024:10806
foreman-proxy-fapolicydRed Hat / RHEL
Fixed in:0:1.0.1-3.el8satRHSA-2024:10806
foreman-redisRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-redisRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-serviceRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-serviceRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-telemetryRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-telemetryRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-vmwareRocky
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
foreman-vmwareRed Hat / RHEL
Fixed in:0:3.9.1.12-1.el8satRHSA-2024:10806
pcsRocky
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
pcsRed Hat / RHEL
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
pcs-snmpRed Hat / RHEL
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
pcs-snmpRocky
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.18-2.el8_10RHSA-2024:2953
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.12-6.el8_6.5RHSA-2024:3431
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.15-4.el8_8.2RHSA-2024:2581
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.4-6.el8_2.5RHSA-2024:2007
Fixed in:0:0.10.8-1.el8_4.5RHSA-2024:2584
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.1-10.el9_0.5RHSA-2024:1841
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.4-7.el9_2.1RHSA-2024:1846
Fixed in:0:0.11.7-2.el9_4RHSA-2024:2113
pulpcore-obsolete-packagesRed Hat / RHEL
Fixed in:0:1.0-10.el8pcRHSA-2024:10806
Fixed in:0:1.0-10.el8pcRHSA-2024:10806
pulpcore-obsolete-packagesRocky
Fixed in:0:1.0-10.el8pcRHSA-2024:10806
Fixed in:0:1.0-10.el8pcRHSA-2024:10806
puppetserverRed Hat / RHEL
Fixed in:0:7.17.2-1.el8satRHSA-2024:10806
Fixed in:0:7.17.2-1.el8satRHSA-2024:10806
puppetserverRocky
Fixed in:0:7.17.2-1.el8satRHSA-2024:10806
Fixed in:0:7.17.2-1.el8satRHSA-2024:10806
python-pulp-containerRed Hat / RHEL
Fixed in:0:2.16.9-2.el8pcRHSA-2024:10806
python-pulp-containerRocky
Fixed in:0:2.16.9-2.el8pcRHSA-2024:10806
python3.11-pulp-containerRed Hat / RHEL
Fixed in:0:2.16.9-2.el8pcRHSA-2024:10806
python3.11-pulp-containerRocky
Fixed in:0:2.16.9-2.el8pcRHSA-2024:10806
rubygem-actioncableRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actioncableRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionmailboxRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionmailboxRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionmailerRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionmailerRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionpackRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionpackRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actiontextRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actiontextRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionviewRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-actionviewRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activejobRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activejobRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activemodelRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activemodelRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activerecordRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activerecordRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activestorageRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activestorageRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activesupportRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-activesupportRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-foreman_rh_cloudRed Hat / RHEL
Fixed in:0:9.0.59-1.el8satRHSA-2024:10806
Fixed in:0:9.0.59-1.el8satRHSA-2024:10806
rubygem-foreman_rh_cloudRocky
Fixed in:0:9.0.59-1.el8satRHSA-2024:10806
Fixed in:0:9.0.59-1.el8satRHSA-2024:10806
rubygem-katelloRed Hat / RHEL
Fixed in:0:4.11.0.19-1.el8satRHSA-2024:10806
Fixed in:0:4.11.0.19-1.el8satRHSA-2024:10806
rubygem-katelloRocky
Fixed in:0:4.11.0.19-1.el8satRHSA-2024:10806
Fixed in:0:4.11.0.19-1.el8satRHSA-2024:10806
rubygem-rackRed Hat / RHEL
Fixed in:0:2.2.8.1-1.el8satRHSA-2024:10806
Fixed in:0:2.2.8.1-1.el8satRHSA-2024:10806
rubygem-rackRocky
Fixed in:0:2.2.8.1-1.el8satRHSA-2024:10806
Fixed in:0:2.2.8.1-1.el8satRHSA-2024:10806
rubygem-railsRocky
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-railsRed Hat / RHEL
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-1.el8satRHSA-2024:10806
rubygem-railtiesRocky
Fixed in:0:6.1.7.7-2.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-2.el8satRHSA-2024:10806
rubygem-railtiesRed Hat / RHEL
Fixed in:0:6.1.7.7-2.el8satRHSA-2024:10806
Fixed in:0:6.1.7.7-2.el8satRHSA-2024:10806
rubygem-smart_proxy_ansibleRocky
Fixed in:0:3.5.6-0.1.el8satRHSA-2024:10806
Fixed in:0:3.5.6-0.1.el8satRHSA-2024:10806
rubygem-smart_proxy_ansibleRed Hat / RHEL
Fixed in:0:3.5.6-0.1.el8satRHSA-2024:10806
Fixed in:0:3.5.6-0.1.el8satRHSA-2024:10806
satelliteRocky
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satelliteRed Hat / RHEL
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satellite-capsuleRocky
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satellite-capsuleRed Hat / RHEL
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satellite-cliRed Hat / RHEL
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satellite-cliRocky
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satellite-commonRed Hat / RHEL
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
satellite-commonRocky
Fixed in:0:6.15.5-1.el8satRHSA-2024:10806
ruby-rackUbuntu
Fixed in:1.5.2-3+deb8u3ubuntu1~esm8USN-6837-2
Fixed in:1.6.4-3ubuntu0.2+esm6USN-6837-2
Fixed in:1.6.4-4ubuntu0.2+esm6USN-6837-2
Fixed in:2.0.7-2ubuntu0.1+esm5USN-6837-2
Fixed in:2.1.4-5ubuntu1+esm5USN-6837-2
Fixed in:2.1.4-5ubuntu1.1USN-7036-1
Fixed in:2.2.4-3ubuntu0.2USN-6837-1
Fixed in:2.2.4-3ubuntu0.1USN-6689-1
Fixed in:2.2.7-1ubuntu0.1USN-6837-1

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityLow

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Exploit Intelligence

2.00%probability of exploitation in 30 days
79thpercentile

Elevated risk: more likely to be exploited than 79% of all known CVEs.

References

Related Vulnerabilities

Other CWE-1333 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2023-3364High7.544%-Fix
CVE-2024-8124High7.540%-Fix
CVE-2024-25126Medium5.335%-Fix
CVE-2024-2651Medium6.533%-Fix
CVE-2021-32837High7.529%-Fix
CVE-2024-2829High7.526%-Fix

Common questions

How do I fix CVE-2024-26146?

Published advisories record a fix for 94 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2024-26146 being actively exploited?

Not that we know of. CVE-2024-26146 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 2.0% is the estimated probability that it will be exploited in the next 30 days. That is higher than 79% of all scored CVEs.

How severe is CVE-2024-26146?

CVE-2024-26146 has a CVSS v3 base score of 5.3, rated medium. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2024-26146 affect?

Published advisories record a fix for ruby-rack (Debian), foreman (Red Hat / RHEL), foreman (Rocky), foreman-cli (Red Hat / RHEL), and 90 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2024-26146
CVE-2024-26146 severity badge

Markdown

[![CVE-2024-26146](https://tridentstack.com/cve/badge/CVE-2024-26146.svg)](https://tridentstack.com/cve/CVE-2024-26146)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-26146"><img src="https://tridentstack.com/cve/badge/CVE-2024-26146.svg" alt="CVE-2024-26146"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-02-14.