CVE-2021-22902

HIGH

Rails 6.0.0-6.0.3.6 and 6.1.0-6.1.3.1 - Denial of Service via Mime Type Parser

Title source: llm
STIX 2.1

Description

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.

References (2)

Core 2
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1138654

Scores

CVSS v3 7.5
EPSS 0.0068
EPSS Percentile 71.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (2)
rubygems/actionpack 6.0.0 - 6.0.3.7RubyGems
rubyonrails/rails 6.0.0 - 6.0.3.7
Published Jun 11, 2021
Tracked Since Feb 18, 2026