CVE-2019-16201

HIGH

Ruby 2.4.0-2.4.7, 2.5.x-2.5.6, 2.6.x-2.6.4 - Denial of Service in WEBrick DigestAuth

Title source: llm
STIX 2.1

Description

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.

Scores

CVSS v3 7.5
EPSS 0.0509
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-287
Status published
Products (2)
debian/debian_linux 8.0
ruby-lang/ruby 2.4.0 - 2.4.7
Published Nov 26, 2019
Tracked Since Feb 18, 2026