Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 RubyGems

Rack vulnerable to Denial of Service

GHSA-hg78-4f6x-99wq · CVE-2018-16470

Published · Modified

Description

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

Ready to move

Start Securing

Free, no credit card | First findings in minutes