Search CVE reports


Toggle filters

1 – 10 of 43 results


CVE-2025-61919

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`,...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61780

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61772

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header block never terminates with the required blank...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61771

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61770

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the first boundary) in memory without any size limit. A...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-59830

Medium priority

Some fixes available 2 of 7

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ;...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-49007

Medium priority
Ignored

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-46727

Medium priority

Some fixes available 6 of 9

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Ignored
Show less packages

CVE-2025-46336

Medium priority

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major...

1 affected package

ruby-rack-session

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-session
Show less packages

CVE-2025-32441

Medium priority
Fixed

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Fixed Fixed Fixed Fixed
Show less packages