-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Security: rack/rack
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unbounded parameter parsing in `Rack::QueryParser` can lead to memory exhaustionGHSA-gjh7-p2fx-99vx published
May 7, 2025 by ioquatixHigh -
`Rack::Session::Pool` middleware may restore deleted sessionsGHSA-vpfw-47h7-xj4g published
May 7, 2025 by ioquatixModerate -
Local file inclusion in `Rack::Static`GHSA-7wqh-767x-r66v published
Mar 10, 2025 by ioquatixHigh -
Possible log Injection in `Rack::Sendfile`GHSA-8cgq-6mh2-7j6v published
Mar 4, 2025 by ioquatixModerate -
Possible log Injection in `Rack::CommonLogger`GHSA-7g2v-jj9q-g3rg published
Feb 12, 2025 by ioquatixModerate -
ReDoS Vulnerability in Rack::Multipart handle_mime_headGHSA-47m2-26rw-j2jw published
Jun 4, 2025 by tenderloveLow -
ReDoS Vulnerability in HTTP Accept Headers ParsingGHSA-cj83-2ww7-mvq7 published
Jul 2, 2024 by ioquatixModerate -
Possible Denial of Service Vulnerability in Rack Header ParsingGHSA-54rr-7fvw-6x8f published
Feb 28, 2024 by tenderloveLow -
Possible DoS Vulnerability with Range Header in RackGHSA-xj5v-6v4g-jfw6 published
Feb 28, 2024 by tenderloveLow -
ReDos in content type parsing (2nd degree polynomial)GHSA-22f2-v57c-j9cx published
Feb 28, 2024 by tenderloveLow