> USN-8190-2: Rack::Session vulnerability
[DATE: 28/04/2026 13:51]
[LANGUAGE: EN]
USN-8190-1 fixed a vulnerability in Rack::Session. This update provides the
corresponding update for Ubuntu 26.04 LTS.
Original advisory details:
SeungMyung Lee discovered that Rack::Session did not properly reject
cookies upon decryption failure. A remote attacker could use this issue to
manipulate session contents and possibly gain unauthorized access.