CVE-2024-25126

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-25126
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-25126.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-25126
Aliases
Downstream
Related
Published
2024-02-28T23:28:07Z
Modified
2025-10-08T23:13:59.523804Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Rack ReDos in content type parsing (2nd degree polynomial)
Details

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.

References

Affected packages

Git / github.com/rack/rack

Affected ranges

Type
GIT
Repo
https://github.com/rack/rack
Events
Type
GIT
Repo
https://github.com/rack/rack
Events
Type
GIT
Repo
https://github.com/rack/rack
Events
Type
GIT
Repo
https://github.com/rack/rack
Events

Affected versions

3.*

3.0.0

v3.*

v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.4.1
v3.0.4.2
v3.0.5
v3.0.6
v3.0.6.1
v3.0.7
v3.0.8
v3.0.9