## What's Changed * Fixed ReDoS in Accept header parsing [CVE-2024-26146] * Fixed ReDoS in Content Type header parsing [CVE-2024-25126] * Reject Range headers which are too large [CVE-2024-26141] **Full Changelog**: https://github.com/rack/rack/compare/v2.2.8...v2.2.8.1