Rack vulnerable to Denial of Service
High severity
GitHub Reviewed
Published
Nov 15, 2018
to the GitHub Advisory Database
•
Updated Nov 4, 2023
Description
Published by the National Vulnerability Database
Nov 13, 2018
Published to the GitHub Advisory Database
Nov 15, 2018
Reviewed
Jun 16, 2020
Last updated
Nov 4, 2023
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
References