VDB
Sign up
HIGH7.5

GHSA-hg78-4f6x-99wq

Rack vulnerable to Denial of Service

Quick fix

GHSA-hg78-4f6x-99wq — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 2.0.4Fixed in: 2.0.6
Fixbundle update rack

References