Executive brief
Rack, a widely used interface for Ruby web applications, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted web request that forces the server to spend an excessive amount of time processing data, effectively freezing the application. This can lead to service outages, preventing legitimate users from accessing the website or application.
Technical details
A vulnerability exists in Rack::Multipart::Parser#handle_mime_head due to inefficient algorithmic complexity (CWE-407). The parser handles quoted multipart parameters using repeated String#index searches combined with destructive String#slice! prefix deletion. For values containing many backslash-escaped characters, this results in super-linear (O(n^2)) processing time. An unauthenticated remote attacker can exploit this by sending a multipart/form-data request containing many parts with long, escape-heavy parameter values. This triggers excessive CPU consumption, leading to a denial of service. The issue is fixed in Rack versions 3.1.21 and 3.2.6.
Affected products
- Rack Rack >= 3.0.0.beta1, < 3.1.21; >= 3.2.0, < 3.2.6
- Red Hat Logging Subsystem for Red Hat OpenShift 5
- Red Hat Red Hat 3scale API Management Platform 2 2
Timeline
- 2026-04-01: advisory: GitHub advisory published by maintainers
- 2026-04-02: disclosed: CVE published to NVD
- 2026-04-02: patched: Patched versions 3.1.21 and 3.2.6 released