Логотип exploitDog
bind:CVE-2025-59830
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-59830

Количество 10

Количество 10

ubuntu логотип

CVE-2025-59830

2 месяца назад

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-59830

2 месяца назад

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-59830

2 месяца назад

Rack is a modular Ruby web server interface. Prior to version 2.2.18, ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251014-01

около 2 месяцев назад

Уязвимость rubygem-rack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-625h-95r8-8xpm

2 месяца назад

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-13146

2 месяца назад

Уязвимость функции QueryParser() интерфейса модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-20962

6 дней назад

ELSA-2025-20962: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-19719

25 дней назад

ELSA-2025-19719: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-19513

24 дня назад

ELSA-2025-19513: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-19512

28 дней назад

ELSA-2025-19512: pcs security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-59830

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-59830

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-59830

Rack is a modular Ruby web server interface. Prior to version 2.2.18, ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
redos логотип
ROS-20251014-01

Уязвимость rubygem-rack

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-625h-95r8-8xpm

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

CVSS3: 7.5
0%
Низкий
2 месяца назад
fstec логотип
BDU:2025-13146

Уязвимость функции QueryParser() интерфейса модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2025-20962

ELSA-2025-20962: pcs security update (IMPORTANT)

6 дней назад
oracle-oval логотип
ELSA-2025-19719

ELSA-2025-19719: pcs security update (IMPORTANT)

25 дней назад
oracle-oval логотип
ELSA-2025-19513

ELSA-2025-19513: pcs security update (IMPORTANT)

24 дня назад
oracle-oval логотип
ELSA-2025-19512

ELSA-2025-19512: pcs security update (IMPORTANT)

28 дней назад

Уязвимостей на страницу