Loading...
Skip to main content

CVE-2025-61771

HIGH

Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)

Published October 7, 2025Updated February 4, 2026Source: osv

Summary

## Summary `Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) conditions and denial of service (DoS). ## Details During multipart parsing, file parts are streamed to temporary files, but non-file parts are buffered into memory: ```ruby body = String.new # non-file → in-RAM buffer @mime_parts[mime_index].body << content ``` There is no size limit on these in-memory buffers. As a result, any large text field—while technically valid—will be loaded fully into process memory before being added to `params`. ## Impact Attackers can send large non-file fields to trigger excessive memory usage. Impact scales with request size and concurrency, potentially leading to worker crashes or severe garbage-collection overhead. All Rack applications processing multipart form submissions are affected. ## Mitigation * **Upgrade:** Use a patched version of Rack that enforces a reasonable size cap for non-file fields (e.g., 2 MiB). * **Workarounds:** * Restrict maximum request body size at the web-server or proxy layer (e.g., Nginx `client_max_body_size`). * Validate and reject unusually large form fields at the application level.

Remediation

Upgrade to the fixed version using your package manager.

Bundler
Update rack to 2.2.19 or later
gem install rack -v 2.2.19
Bundler
Update rack to 3.1.17 or later
gem install rack -v 3.1.17
Bundler
Update rack to 3.2.2 or later
gem install rack -v 3.2.2

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (3)

PackageEcosystemAffectedFixed In
rack
rubygems
0.1.0, 0.2.0, 0.3.0, 0.4.0 (+115 more)2.2.19
rack
rubygems
3.1.0, 3.1.1, 3.1.10, 3.1.11 (+13 more)3.1.17
rack
rubygems
3.2.0, 3.2.13.2.2

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-400
    Uncontrolled Resource ConsumptionMITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Frequently Asked Questions

What is CVE-2025-61771?
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion) This vulnerability has been assigned a severity rating of HIGH (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2025-61771?
CVE-2025-61771 affects rack. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-61771 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-w9pc-fmgc-vxvw

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies