CVE-2025-27111 | Rack up to 2.2.11/3.0.12/3.1.10 Header Rack::Sendfile X-Sendfile-Type crlf injection (Nessus ID 232155)
A vulnerability marked as problematic has been reported in Rack up to 2.2.11/3.0.12/3.1.10. The impacted element is the function Rack::Sendfile of the component Header Handler. The manipulation of the argument X-Sendfile-Type leads to crlf injection.
This vulnerability is uniquely identified as CVE-2025-27111. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.