Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15 advisories

Filter by severity
Loading
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing High
CVE-2025-61919 was published for rack (RubyGems) Oct 10, 2025
Pirikarajeremyevans
ioquatix
Credited to Pirikara, jeremyevans, and ioquatix
Rack has a Possible Information Disclosure Vulnerability Moderate
CVE-2025-61780 was published for rack (RubyGems) Oct 10, 2025
leahneukirchenjeremyevans
matthewdioquatix
Credited to leahneukirchen, jeremyevans, matthewd, and ioquatix
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion) High
CVE-2025-61772 was published for rack (RubyGems) Oct 7, 2025
kwkrjeremyevans
ioquatix
Credited to kwkr, jeremyevans, and ioquatix
kwkrjeremyevans
ioquatix
Credited to kwkr, jeremyevans, and ioquatix
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) High
CVE-2025-61770 was published for rack (RubyGems) Oct 7, 2025
kwkrioquatix
jeremyevans
Credited to kwkr, ioquatix, and jeremyevans
kwkrjeremyevans
ioquatix
Credited to kwkr, jeremyevans, and ioquatix
Rack has an Unbounded-Parameter DoS in Rack::QueryParser High
CVE-2025-46727 was published for rack (RubyGems) May 8, 2025
TaiPhung217jeremyevans
ioquatix
Credited to TaiPhung217, jeremyevans, and ioquatix
Rack session gets restored after deletion Moderate
CVE-2025-46336 was published for rack-session (RubyGems) May 8, 2025
stengineering0jeremyevans
ioquatix
Credited to stengineering0, jeremyevans, and ioquatix
Rack session gets restored after deletion Moderate
CVE-2025-32441 was published for rack (RubyGems) May 8, 2025
stengineering0jeremyevans
ioquatix
Credited to stengineering0, jeremyevans, and ioquatix
Local File Inclusion in Rack::Static High
CVE-2025-27610 was published for rack (RubyGems) Mar 10, 2025
Masamuneeejeremyevans
ioquatix
Credited to Masamuneee, jeremyevans, and ioquatix
Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection Moderate
CVE-2025-27111 was published for rack (RubyGems) Mar 4, 2025
Masamuneeeioquatix
jeremyevans
Credited to Masamuneee, ioquatix, and jeremyevans
Possible Log Injection in Rack::CommonLogger Moderate
CVE-2025-25184 was published for rack (RubyGems) Feb 12, 2025
HexSavejeremyevans
ioquatixtaketo1113nick-fvladimir-mencl-eresearchlostapathymatthewbjoneslfittl
Credited to HexSave, jeremyevans, ioquatix, taketo1113, nick-f, vladimir-mencl-eresearch, lostapathy, matthewbjones, and lfittl
Sim4n6ioquatix
Credited to Sim4n6 and ioquatix
protocol-http1 HTTP Request/Response Smuggling vulnerability Moderate
CVE-2023-38697 was published for protocol-http1 (RubyGems) Aug 3, 2023
mukeranchenjj
ioquatix
Credited to mukeran, chenjj, and ioquatix
Puma's Keepalive Connections Causing Denial Of Service High
CVE-2021-29509 was published for puma (RubyGems) May 18, 2021
MSP-Gregwjordan
ioquatix
Credited to MSP-Greg, wjordan, and ioquatix
ProTip! Advisories are also available from the GraphQL API