Home

Description

There is a denial of service vulnerability in the header parsing component of Rack.

PUBLISHED Reserved 2023-03-02 | Published 2025-01-09 | Updated 2025-01-09 | Assigner hackerone

Product status

Default status
unaffected

2.2.6.4 (custom) before 2.2.6.4
affected

3.0.6.1 (custom) before 3.0.6.1
affected

References

discuss.rubyonrails.org/...ity-in-racks-header-parsing/82466

github.com/advisories/GHSA-c6qg-cjj8-47qp

github.com/...ommit/231ef369ad0b542575fb36c74fcfcfabcf6c530c

github.com/...ommit/ee7919ea04303717858be1c3f16b406adc6d8cff

lists.debian.org/debian-lts-announce/2023/04/msg00017.html

security.netapp.com/advisory/ntap-20231208-0016/

www.debian.org/security/2023/dsa-5530

cve.org (CVE-2023-27539)

nvd.nist.gov (CVE-2023-27539)

Download JSON