Loading...
Skip to main content

CVE-2025-46727

HIGH

Rack has an Unbounded-Parameter DoS in Rack::QueryParser

Published May 8, 2025Updated February 4, 2026Source: osv

Summary

## Summary `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. ## Details The vulnerability arises because `Rack::QueryParser` iterates over each `&`-separated key-value pair and adds it to a Hash without enforcing an upper bound on the total number of parameters. This allows an attacker to send a single request containing hundreds of thousands (or more) of parameters, which consumes excessive memory and CPU during parsing. ## Impact An attacker can trigger denial of service by sending specifically crafted HTTP requests, which can cause memory exhaustion or pin CPU resources, stalling or crashing the Rack server. This results in full service disruption until the affected worker is restarted. ## Mitigation - Update to a version of Rack that limits the number of parameters parsed, or - Use middleware to enforce a maximum query string size or parameter count, or - Employ a reverse proxy (such as Nginx) to limit request sizes and reject oversized query strings or bodies. Limiting request body sizes and query string lengths at the web server or CDN level is an effective mitigation.

Remediation

Upgrade to the fixed version using your package manager.

Bundler
Update rack to 2.2.14 or later
gem install rack -v 2.2.14
Bundler
Update rack to 3.1.14 or later
gem install rack -v 3.1.14
Bundler
Update rack to 3.0.16 or later
gem install rack -v 3.0.16

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (3)

PackageEcosystemAffectedFixed In
rack
rubygems
0.1.0, 0.2.0, 0.3.0, 0.4.0 (+110 more)2.2.14
rack
rubygems
3.1.0, 3.1.1, 3.1.10, 3.1.11 (+10 more)3.1.14
rack
rubygems
3.0.0, 3.0.1, 3.0.10, 3.0.11 (+16 more)3.0.16

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-400
    Uncontrolled Resource ConsumptionMITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Frequently Asked Questions

What is CVE-2025-46727?
Rack has an Unbounded-Parameter DoS in Rack::QueryParser This vulnerability has been assigned a severity rating of HIGH (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2025-46727?
CVE-2025-46727 affects rack. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-46727 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-gjh7-p2fx-99vx

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies