CVE-2025-27111

unknown
Published 2025-03-04 · Modified 2026-02-04
CVSS v3
CVSS v2
VIR risk

Description

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-27111

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-27111.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed2.2.13-1~deb12u1
debian debianbullseyefixed2.1.4-3+deb11u3
debian debianforkyfixed3.1.12-1
debian debiansidfixed3.1.12-1
debian debiantrixiefixed3.1.12-1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsrack<~> 2.2.12~> 2.2.12
ruby RubyGemsrack<2.2.122.2.12
ruby RubyGemsrack>=3.0,<3.0.133.0.13
ruby RubyGemsrack>=3.1,<3.1.113.1.11

References

Verify integrity in audit chain (admin only). AS-IS.