CVE-2023-27530

HIGH

Rack <2.0.9.3 - Denial of Service via Multipart MIME Parsing

Title source: llm
STIX 2.1

Description

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

Scores

CVSS v3 7.5
EPSS 0.0198
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770 CWE-400
Status published
Products (4)
debian/debian_linux 10.0
debian/debian_linux 11.0
rack/rack < 2.0.9.3
rubygems/rack 0 - 2.0.9.3RubyGems
Published Mar 10, 2023
Tracked Since Feb 18, 2026