In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
History

Wed, 23 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

Thu, 20 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
References

Wed, 05 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Ruby-lang
Ruby-lang cgi
CPEs cpe:2.3:a:ruby-lang:cgi:*:*:*:*:*:ruby:*:*
cpe:2.3:a:ruby-lang:cgi:0.3.6:*:*:*:*:ruby:*:*
Vendors & Products Ruby-lang
Ruby-lang cgi

Tue, 04 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Title CGI: Denial of Service in CGI::Cookie.parse
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 03 Mar 2025 23:45:00 +0000

Type Values Removed Values Added
Description In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-04T16:41:20.234Z

Reserved: 2025-02-20T00:00:00.000Z

Link: CVE-2025-27219

cve-icon Vulnrichment

Updated: 2025-03-04T16:41:16.608Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-04T00:15:31.550

Modified: 2025-03-05T14:05:15.387

Link: CVE-2025-27219

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-03T00:00:00Z

Links: CVE-2025-27219 - Bugzilla