CVE-2025-61780 | Rack up to 2.2.19/3.1.17/3.2.2 Header Rack::Sendfile x-sendfile information disclosure (GHSA-r657-rxjc-j557)
A vulnerability classified as problematic has been found in Rack up to 2.2.19/3.1.17/3.2.2. The affected element is the function Rack::Sendfile of the component Header Handler. This manipulation of the argument x-sendfile causes information disclosure.
The identification of this vulnerability is CVE-2025-61780. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.