CVE-2018-16470
HIGHRack < 2.0.6 - Denial of Service via Multipart Parser
Title source: llmDescription
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
References (2)
Core 2
Core References
Mailing List x_refsource_misc
https://groups.google.com/forum/#%21msg/rubyonrails-security/U_x-YkfuVTg/xhvYAmp6AAAJ
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3172
Scores
CVSS v3
7.5
EPSS
0.0018
EPSS Percentile
38.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (3)
rack_project/rack
2.0.4
rack_project/rack
2.0.5
rubygems/rack
2.0.4 - 2.0.6RubyGems
Published
Nov 13, 2018
Tracked Since
Feb 18, 2026