Executive brief
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
Affected products
- RubyGems rack
Junglewise Threat Intelligence
CVE-2025-59830 · Severity: low · CVSS 3.1 · Published 2025-09-25
Technologies: rack (RubyGems). Vendors: RubyGems.
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters