Rack::Session::Pool of the component Session Cookie Handler. Such manipulation leads to race condition.This vulnerability is listed as CVE-2025-46336. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.