<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:00:58.288118+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02580</id>
    <title>bdu:2024-02580</title>
    <updated>2026-10-03T01:00:58.399034+00:00</updated>
    <content>bdu:2024-02580</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-travis-cve-2022-44571</id>
    <title>BREW-travis-CVE-2022-44571 — Denial of Service Vulnerability in Rack Content-Disposition parsing</title>
    <updated>2026-10-03T01:00:58.399072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: travis</p>
<p>There is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2022-44571.</p>
<p>Versions Affected: &gt;= 2.0.0 Not affected: None. Fixed Versions: 2.0.9.2, 2.1.4.2, 2.2.6.1, 3.0.0.1
Impact</p>
<p>Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is used typically used in multipart parsing. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.
Releases</p>
<p>The fixed releases are available at the normal locations.
Workarounds</p>
<p>There are no feasible workarounds for this issue.
Patches</p>
<p>To aid users who aren’t able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>2-0-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 2.0 series
    2-1-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 2.1 series
    2-2-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 2.2 series
    3-0-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 3.0 series</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-travis-cve-2022-44571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-19660</id>
    <title>EUVD-2026-19660</title>
    <updated>2026-10-03T01:00:58.399124+00:00</updated>
    <content>EUVD-2026-19660</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-19660"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-44571</id>
    <title>fkie_cve-2022-44571</title>
    <updated>2026-10-03T01:00:58.399139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of time, possibly resulting in a denial ofservice attack vector. This header is used typically used in multipartparsing. Any applications that parse multipart posts using Rack (virtuallyall Rails applications) are impacted.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-44571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-93pm-5p5f-3ghx</id>
    <title>GHSA-93pm-5p5f-3ghx — Denial of Service Vulnerability in Rack Content-Disposition parsing</title>
    <updated>2026-10-03T01:00:58.399164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rack</p>
<p>There is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This vulnerability has been assigned the CVE identifier CVE-2022-44571.</p>
<p>Versions Affected: &gt;= 2.0.0 Not affected: None. Fixed Versions: 2.0.9.2, 2.1.4.2, 2.2.6.1, 3.0.0.1
Impact</p>
<p>Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is used typically used in multipart parsing. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.
Releases</p>
<p>The fixed releases are available at the normal locations.
Workarounds</p>
<p>There are no feasible workarounds for this issue.
Patches</p>
<p>To aid users who aren’t able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>2-0-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 2.0 series
    2-1-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 2.1 series
    2-2-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 2.2 series
    3-0-Fix-ReDoS-vulnerability-in-multipart-parser - Patch for 3.0 series</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-93pm-5p5f-3ghx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-44571</id>
    <title>gsd-2022-44571</title>
    <updated>2026-10-03T01:00:58.399202+00:00</updated>
    <content>gsd-2022-44571</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-44571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2032</id>
    <title>OESA-2024-2032 — rubygem-rack security update</title>
    <updated>2026-10-03T01:00:58.399214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: rubygem-rack</p>
<p>Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.

Security Fix(es):

A denial of service vulnerability in the Range header parsing component of Rack &amp;gt;= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.(CVE-2022-44570)

There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of time, possibly resulting in a denial ofservice attack vector. This header is used typically used in multipartparsing. Any applications that parse multipart posts using Rack (virtuallyall Rails applications) are impacted.(CVE-2022-44571)

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree po…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12633-1</id>
    <title>openSUSE-SU-2024:12633-1 — ruby3.1-rubygem-rack-3.0.4.1-1.1 on GA media</title>
    <updated>2026-10-03T01:00:58.399266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby3.1-rubygem-rack-3.0.4.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12633-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:6818</id>
    <title>RHSA-2023:6818 — Red Hat Security Advisory: Satellite 6.14 security and bug fix update</title>
    <updated>2026-10-03T01:00:58.399287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubeclient: kubeconfig parsing error can lead to MITM attacks openssl: c_rehash script allows command injection openssl: the c_rehash script allows command injection Pulp: Tokens stored in plaintext foreman: OS command injection via ct_command and fcct_command satellite: Blind SSRF via Referer header python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests rubygem-activerecord: Denial of Service rubygem-rack: denial of service in Content-Disposition parsing rubygem-rack: denial of service in Content-Disposition parsing rubygem-rack: denial of service in Content-Disposition parsing ruby-git: code injection vulnerability ruby-git: code injection vulnerability Foreman: Arbitrary code execution through templates Foreman: Stored cross-site scripting in host tab puppet: Puppet Server ReDoS rubygem-actionpack: Denial of Service in Action Dispatch rubygem-activerecord: SQL Injection rubygem-actionpack: Denial of Service in Action Dispatch rubygem-activesupport: Regular Expression Denial of Service rubygem-globalid: ReDoS vulnerability rubygem-rack: Denial of service in Multipart MIME parsing rubygem-rack: denial of service in header parsing golang: net/http: insufficient sanitization of Host header sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) python-django: Potential bypass o…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:6818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0276-1</id>
    <title>SUSE-SU-2023:0276-1 — Security update for rubygem-rack</title>
    <updated>2026-10-03T01:00:58.399350+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-rack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0276-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-44571</id>
    <title>UBUNTU-CVE-2022-44571</title>
    <updated>2026-10-03T01:00:58.399366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:Pro:16.04:LTS: ruby-rack, Ubuntu:Pro:18.04:LTS: ruby-rack, Ubuntu:Pro:20.04:LTS: ruby-rack, Ubuntu:22.04:LTS: ruby-rack, Ubuntu:Pro:22.04:LTS: ruby-rack</p>
<p>There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of time, possibly resulting in a denial ofservice attack vector. This header is used typically used in multipartparsing. Any applications that parse multipart posts using Rack (virtuallyall Rails applications) are impacted.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-44571"/>
  </entry>
</feed>
