Description
There is a denial of service vulnerability in the header parsing component of Rack.
References (7)
Core 7
Core References
Vendor Advisory
https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466
Patch, Third Party Advisory
https://github.com/advisories/GHSA-c6qg-cjj8-47qp
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20231208-0016/
Mailing List, Third Party Advisory
https://www.debian.org/security/2023/dsa-5530
Scores
CVSS v3
5.3
EPSS
0.0036
EPSS Percentile
58.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (4)
debian/debian_linux
10.0
debian/debian_linux
11.0
rack/rack
2.0.0 - 2.2.6.4
rubygems/rack
2.0.0 - 2.2.6.4RubyGems
Published
Jan 09, 2025
Tracked Since
Feb 18, 2026