HIGH 7.5 RubyGems

Rack vulnerable to Denial of Service

GHSA-hg78-4f6x-99wq · CVE-2018-16470

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

Ready to move

Start Securing

Free, no credit card | First findings in minutes