Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3800-1 | ruby-rack security update |
Debian DSA |
DSA-5698-1 | ruby-rack security update |
EUVD |
EUVD-2024-0516 | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1. |
Github GHSA |
GHSA-54rr-7fvw-6x8f | Rack Header Parsing leads to Possible Denial of Service Vulnerability |
Ubuntu USN |
USN-6689-1 | Rack vulnerabilities |
Ubuntu USN |
USN-6837-1 | Rack vulnerabilities |
Ubuntu USN |
USN-6837-2 | Rack vulnerabilities |
Ubuntu USN |
USN-7036-1 | Rack vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Rack Rack rack |
|
| CPEs | cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Rack Rack rack |
Thu, 13 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1. | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is fixed in 2.0.9.4, 2.1.4.4, 2.2.8.1, and 3.0.9.1. |
Thu, 05 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat satellite
Redhat satellite Capsule |
|
| CPEs | cpe:/a:redhat:satellite:6.15::el8 cpe:/a:redhat:satellite_capsule:6.15::el8 |
|
| Vendors & Products |
Redhat satellite
Redhat satellite Capsule |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:41:07.669Z
Reserved: 2024-02-14T17:40:03.689Z
Link: CVE-2024-26146
Updated: 2024-08-01T23:59:32.576Z
Status : Analyzed
Published: 2024-02-29T00:15:51.597
Modified: 2025-02-14T15:51:42.200
Link: CVE-2024-26146
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN