cbcvebase.
CVE-2023-27539
published 2025-01-09

CVE-2023-27539: There is a denial of service vulnerability in the header parsing component of Rack.

PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.08%
61.7th percentile
There is a denial of service vulnerability in the header parsing component of Rack.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianruby-rack< ruby-rack 2.2.6.4-1 (bookworm)ruby-rack 2.2.6.4-1 (bookworm)
rackrack>= 2.0.0 < 2.2.6.42.2.6.4
rackrack>= 2.0.0 < 2.2.6.42.2.6.4
rackrack>= 3.0.0 < 3.0.6.13.0.6.1
rackrack>= 3.0.0 < 3.0.6.13.0.6.1
railsrack>= 2.2.6.4 < 2.2.6.42.2.6.4
railsrack>= 3.0.6.1 < 3.0.6.13.0.6.1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ghsa5.3MEDIUM
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.