GHSA-7g2v-jj9q-g3rg
Possible Log Injection in Rack::CommonLogger
Quick fix
GHSA-7g2v-jj9q-g3rg — rack: upgrade to the fixed version with the command below.
bundle update rackDetails
## Summary
`Rack::CommonLogger` can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content into logs.
## Details
When a user provides the authorization credentials via `Rack::Auth::Basic`, if success, the username will be put in `env['REMOTE_USER']` and later be used by `Rack::CommonLogger` for logging purposes.
The issue occurs when a server intentionally or unintentionally allows a user creation with the username contain CRLF and white space characters, or the server just want to log every login attempts. If an attacker enters a username with CRLF character, the logger will log the malicious username with CRLF characters into the logfile.
## Impact
Attackers can break log formats or insert fraudulent entries, potentially obscuring real activity or injecting malicious data into log files.
## Mitigation
- Update to the latest version of Rack.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rack/rack/security/advisories/GHSA-7g2v-jj9q-g3rg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-25184[ADVISORY]
- https://github.com/rack/rack/commit/074ae244430cda05c27ca91cda699709cfb3ad8e[WEB]
- https://github.com/rack/rack[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2025-25184.yml[WEB]
- https://lists.debian.org/debian-lts-announce/2025/03/msg00016.html[WEB]