Hello team, I've backported security fixes for ruby-rack from upstream 2.2.23 to bullseye version 2.1.4.[1] One extra thing I did is adding a test case[2] from upstream for CVE-2026-26961[2] which is completely optional.
It will be lovely, if someone can review and give feedback. Debdiff also attached. --abhijith [1] - https://salsa.debian.org/ruby-team/ruby-rack/-/commit/76ad0eca8a42c65c58835a95de8c91ae7ac811f8 [2] - https://salsa.debian.org/ruby-team/ruby-rack/-/blob/76ad0eca8a42c65c58835a95de8c91ae7ac811f8/debian/patches/CVE-2026-26961-1.patch
