Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59830


Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.


Published

2025-09-25T15:16:13.780

Last Modified

2025-10-10T16:43:14.337

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-400
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rack rack < 2.2.18 Yes

References