Rack Gem Subject to Denial of Service via Hash Collisions
Modified: 11/30/2024
package
pkg:rubygems/rack
Rack Gem Subject to Denial of Service via Hash Collisions
Modified: 11/30/2024
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
Modified: 9/10/2026
Rack has possible DoS Vulnerability in Multipart MIME parsing
Modified: 2/13/2025
Rack rubygems receiving excessively long lines triggers out-of-memory error
Modified: 12/3/2024
ReDoS Vulnerability in Rack::Multipart handle_mime_head
Modified: 9/10/2026
Rack Header Parsing leads to Possible Denial of Service Vulnerability
Modified: 9/10/2026
Directory traversal in Rack::Directory app bundled with Rack
Modified: 9/10/2026
Rack vulnerable to Cross-site Scripting
Modified: 2/18/2024
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
Modified: 9/10/2026
Denial of service via header parsing in Rack
Modified: 2/13/2025
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
Modified: 9/10/2026
Possible Log Injection in Rack::CommonLogger
Modified: 9/10/2026
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
Modified: 9/10/2026
Local File Inclusion in Rack::Static
Modified: 9/10/2026
Rack Vulnerable to Path Traversal
Modified: 11/29/2024
Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Modified: 9/10/2026
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
Modified: 9/10/2026
Denial of Service Vulnerability in Rack Content-Disposition parsing
Modified: 12/1/2024
Possible Denial of Service Vulnerability in Rack's header parsing
Modified: 1/9/2025
Rack ReDoS Vulnerability in HTTP Accept Headers Parsing
Modified: 2/4/2026
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
Modified: 9/10/2026
Rack has an Unbounded-Parameter DoS in Rack::QueryParser
Modified: 9/10/2026
Rack::Static prefix matching can expose unintended files under the static root
Modified: 9/10/2026
Rack vulnerable to REDoS
Modified: 11/29/2024
Rack vulnerable to Denial of Service
Modified: 2/16/2024
Possible Information Leak / Session Hijack Vulnerability in Rack
Modified: 9/10/2026
Denial of Service Vulnerability in Rack Multipart Parsing
Modified: 2/18/2024
Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names
Modified: 9/10/2026
Rack has a Directory Traversal via Rack:Directory
Modified: 9/10/2026
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
Modified: 9/10/2026
Rack has Content-Length mismatch in Rack::Files error responses
Modified: 9/10/2026
Rack:: Static header_rules bypass via URL-encoded paths
Modified: 9/10/2026
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
Modified: 9/10/2026
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
Modified: 9/10/2026
Rack has a Possible Information Disclosure Vulnerability
Modified: 9/10/2026
Rack vulnerable to Denial of Service via large parameter depth request
Modified: 12/3/2024
Denial of service via multipart parsing in Rack
Modified: 12/1/2024
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
Modified: 9/10/2026
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
Modified: 9/10/2026
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
Modified: 9/10/2026
Rack vulnerable to Denial of Service
Modified: 12/7/2024
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
Modified: 9/10/2026
Rack session gets restored after deletion
Modified: 9/10/2026
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
Modified: 9/10/2026
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
Modified: 9/10/2026
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
Modified: 9/10/2026
Possible shell escape sequence injection vulnerability in Rack
Modified: 2/18/2024
Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
Modified: 9/10/2026
Rack arbitrary code execution via timing attack
Modified: 12/5/2024
Rack has possible DoS Vulnerability with Range Header
Modified: 9/10/2026