CVE-2025-49007

unknown
Published 2025-06-05 · Modified 2026-02-04
CVSS v3
CVSS v2
VIR risk

Description

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to the previous security issue CVE-2022-44571. Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is used typically used in multipart parsing. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted. Version 3.1.16 contains a patch for the vulnerability.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-49007

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-49007.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed3.1.16-0.1
debian debiansidfixed3.1.16-0.1
debian debiantrixiefixed3.1.16-0.1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsrack!< 3.1.0||<>= 3.1.16>= 3.1.16
ruby RubyGemsrack>=3.1.0,<3.1.163.1.16

References

Verify integrity in audit chain (admin only). AS-IS.