Skip to content
Noroxi

rack records

39 published records for vendor rack.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

39 records
  • Rack ReDos in content type parsing (2nd degree polynomial)

    HighCVSS 7.5No exploitEPSS 35%

    rack · rackFeb 28, 2024

  • Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization

    CriticalCVSS 9.3Proof of conceptEPSS 0%

    rack · rack-sessionApr 7, 2026

  • rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter

    HighCVSS 8.6No exploitEPSS 1%

    rack · rack-contribMay 27, 2024

  • Possible Denial of Service Vulnerability in Rack Header Parsing

    HighCVSS 7.5No exploitEPSS 2%

    rack · rackFeb 28, 2024

  • A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could al

    HighCVSS 7.5No exploitEPSS 2%

    rack · rackMar 10, 2023

  • A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0.

    HighCVSS 7.5No exploitEPSS 2%

    rack · rackFeb 9, 2023

  • A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an a

    HighCVSS 7.5No exploitEPSS 2%

    rack · rackFeb 9, 2023

  • Possible DoS Vulnerability with Range Header in Rack

    HighCVSS 7.5No exploitEPSS 2%

    rack · rackFeb 28, 2024

  • There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1.

    HighCVSS 7.5No exploitEPSS 2%

    rack · rackFeb 9, 2023

  • Unbounded-Parameter DoS in Rack::QueryParser

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackMay 7, 2025

  • Local File Inclusion in Rack::Static

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackMar 10, 2025

  • Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackOct 7, 2025

  • Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackOct 7, 2025

  • Rack has a Directory Traversal via Rack:Directory

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackFeb 18, 2026

  • Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackApr 2, 2026

  • Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackApr 2, 2026

  • Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackOct 10, 2025

  • Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackSep 25, 2025

  • Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackOct 7, 2025

  • Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching

    HighCVSS 7.5No exploitEPSS 1%

    rack · rackApr 2, 2026

  • Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

    HighCVSS 7.5No exploitEPSS 0%

    rack · rackApr 2, 2026

  • Rack: Unbounded Range Count in get_byte_ranges Enables DoS

    HighCVSS 7.5No exploitEPSS 0%

    rack · rackApr 2, 2026

  • Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx

    HighCVSS 7.5No exploitEPSS 0%

    rack · rackApr 2, 2026

  • Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection

    MediumCVSS 6.9No exploitEPSS 1%

    rack · rackMar 4, 2025

  • Rack ReDoS Vulnerability in HTTP Accept Headers Parsing

    MediumCVSS 6.5No exploitEPSS 1%

    rack · rackJul 2, 2024