<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:52:10.091240+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-04200</id>
    <title>bdu:2022-04200</title>
    <updated>2026-10-02T20:52:10.151619+00:00</updated>
    <content>bdu:2022-04200</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-04200"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2022-30122</id>
    <title>BREW-mailcatcher-CVE-2022-30122 — Denial of Service Vulnerability in Rack Multipart Parsing</title>
    <updated>2026-10-02T20:52:10.151667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: mailcatcher</p>
<p>There is a possible denial of service vulnerability in the multipart parsing component of Rack.  This vulnerability has been assigned the CVE identifier CVE-2022-30122.</p>
<p>Versions Affected:  &gt;= 1.2
Not affected:       &lt; 1.2
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1</p>
<p>## Impact
Carefully crafted multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.</p>
<p>Impacted code will use Rack's multipart parser to parse multipart posts.  This includes directly using the multipart parser like this:</p>
<p>```
params = Rack::Multipart.parse_multipart(env)
```</p>
<p>But it also includes reading POST data from a Rack request object like this:</p>
<p>```
p request.POST # read POST data
p request.params # reads both query params and POST data
```</p>
<p>All users running an affected release should either upgrade or use one of the workarounds immediately.</p>
<p>## Workarounds
There are no feasible workarounds for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2022-30122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-506</id>
    <title>certfr-2022-avi-506 — De multiples vulnérabilités ont été découvertes dans Ruby on Rails .
Elles permettent à un attaquant de provoquer une e…</title>
    <updated>2026-10-02T20:52:10.151715+00:00</updated>
    <content>certfr-2022-avi-506</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-506"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-202803</id>
    <title>EUVD-2026-202803</title>
    <updated>2026-10-02T20:52:10.151732+00:00</updated>
    <content>EUVD-2026-202803</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-202803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30122</id>
    <title>fkie_cve-2022-30122</title>
    <updated>2026-10-02T20:52:10.151744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A possible denial of service vulnerability exists in Rack &lt;2.0.9.1, &lt;2.1.4.1 and &lt;2.2.3.1 in the multipart parsing component of Rack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-30122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hxqx-xwvh-44m2</id>
    <title>GHSA-hxqx-xwvh-44m2 — Denial of Service Vulnerability in Rack Multipart Parsing</title>
    <updated>2026-10-02T20:52:10.151765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rack</p>
<p>There is a possible denial of service vulnerability in the multipart parsing component of Rack.  This vulnerability has been assigned the CVE identifier CVE-2022-30122.</p>
<p>Versions Affected:  &gt;= 1.2
Not affected:       &lt; 1.2
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1</p>
<p>## Impact
Carefully crafted multipart POST requests can cause Rack's multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.</p>
<p>Impacted code will use Rack's multipart parser to parse multipart posts.  This includes directly using the multipart parser like this:</p>
<p>```
params = Rack::Multipart.parse_multipart(env)
```</p>
<p>But it also includes reading POST data from a Rack request object like this:</p>
<p>```
p request.POST # read POST data
p request.params # reads both query params and POST data
```</p>
<p>All users running an affected release should either upgrade or use one of the workarounds immediately.</p>
<p>## Workarounds
There are no feasible workarounds for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hxqx-xwvh-44m2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-30122</id>
    <title>gsd-2022-30122</title>
    <updated>2026-10-02T20:52:10.151798+00:00</updated>
    <content>gsd-2022-30122</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-30122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1729</id>
    <title>OESA-2022-1729 — rubygem-rack security update</title>
    <updated>2026-10-02T20:52:10.151810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack</p>
<p>Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.

Security Fix(es):

Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)

Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)

A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12119-1</id>
    <title>openSUSE-SU-2024:12119-1 — ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media</title>
    <updated>2026-10-02T20:52:10.151838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12119-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7242</id>
    <title>RHSA-2022:7242 — Red Hat Security Advisory: Satellite 6.11.4 Async Security Update</title>
    <updated>2026-10-02T20:52:10.151857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-rack: crafted multipart POST request may cause a DoS rubygem-tzinfo: arbitrary code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2192-1</id>
    <title>SUSE-SU-2022:2192-1 — Security update for rubygem-rack</title>
    <updated>2026-10-02T20:52:10.151873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-rack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2192-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30122</id>
    <title>UBUNTU-CVE-2022-30122</title>
    <updated>2026-10-02T20:52:10.151887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:Pro:16.04:LTS: ruby-rack, Ubuntu:Pro:18.04:LTS: ruby-rack, Ubuntu:Pro:20.04:LTS: ruby-rack, Ubuntu:22.04:LTS: ruby-rack, Ubuntu:Pro:22.04:LTS: ruby-rack</p>
<p>A possible denial of service vulnerability exists in Rack &lt;2.0.9.1, &lt;2.1.4.1 and &lt;2.2.3.1 in the multipart parsing component of Rack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0262</id>
    <title>WID-SEC-W-2022-0262 — Ruby: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:52:10.151930+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0262"/>
  </entry>
</feed>
