Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) conditions and denial of service (DoS). Attackers can send large non-file fields to trigger excessive memory usage. Impact scales with request size and concurrency, potentially leading to worker crashes or severe garbage-collection overhead. All Rack applications processing multipart form submissions are affected. Versions 2.2.19, 3.1.17, and 3.2.2 enforce a reasonable size cap for non-file fields (e.g., 2 MiB). Workarounds include restricting maximum request body size at the web-server or proxy layer (e.g., Nginx `client_max_body_size`) and validating and rejecting unusually large form fields at the application level.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade pcsUpgrade pcs-snmp | Nov 21, 2025 | Nov 4, 2025 |
| Amazon Linux Ami 2 | — | Upgrade pcs-snmpUpgrade pcs-debuginfoUpgrade pcs | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade ruby-rack | Nov 4, 2025 | Nov 4, 2025 |
| Oracle_linux | — | Upgrade pcsUpgrade cockpit-ha-clusterUpgrade pcs-snmp | Nov 5, 2025 | Oct 7, 2025 |
| Redhat_linux | — | Upgrade pcs-debuginfoUpgrade pcs-snmpUpgrade cockpit-ha-clusterUpgrade pcs | Nov 5, 2025 | Oct 7, 2025 |
| Rocky_linux | — | Upgrade pcsUpgrade pcs-snmp | Feb 5, 2026 | Nov 21, 2025 |
| Ubuntu | — | Upgrade ruby-rackUpgrade ruby-rack (Ubuntu Pro) | Jan 16, 2026 | Jan 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub