<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:36:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04200</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04200</link>
      <description>bdu:2022-04200</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04200</guid>
    </item>
    <item>
      <title>BREW-mailcatcher-CVE-2022-30122 — Denial of Service Vulnerability in Rack Multipart Parsing</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2022-30122</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;There is a possible denial of service vulnerability in the multipart parsing component of Rack.  This vulnerability has been assigned the CVE identifier CVE-2022-30122.&lt;/p&gt;
&lt;p&gt;Versions Affected:  &amp;gt;= 1.2
Not affected:       &amp;lt; 1.2
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted multipart POST requests can cause Rack&amp;#39;s multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.&lt;/p&gt;
&lt;p&gt;Impacted code will use Rack&amp;#39;s multipart parser to parse multipart posts.  This includes directly using the multipart parser like this:&lt;/p&gt;
&lt;p&gt;```
params = Rack::Multipart.parse_multipart(env)
```&lt;/p&gt;
&lt;p&gt;But it also includes reading POST data from a Rack request object like this:&lt;/p&gt;
&lt;p&gt;```
p request.POST # read POST data
p request.params # reads both query params and POST data
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
There are no feasible workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;There is a possible denial of service vulnerability in the multipart parsing component of Rack.  This vulnerability has been assigned the CVE identifier CVE-2022-30122.&lt;/p&gt;
&lt;p&gt;Versions Affected:  &amp;gt;= 1.2
Not affected:       &amp;lt; 1.2
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted multipart POST requests can cause Rack&amp;#39;s multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.&lt;/p&gt;
&lt;p&gt;Impacted code will use Rack&amp;#39;s multipart parser to parse multipart posts.  This includes directly using the multipart parser like this:&lt;/p&gt;
&lt;p&gt;```
params = Rack::Multipart.parse_multipart(env)
```&lt;/p&gt;
&lt;p&gt;But it also includes reading POST data from a Rack request object like this:&lt;/p&gt;
&lt;p&gt;```
p request.POST # read POST data
p request.params # reads both query params and POST data
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
There are no feasible workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2022-30122</guid>
    </item>
    <item>
      <title>certfr-2022-avi-506 — De multiples vulnérabilités ont été découvertes dans Ruby on Rails .
Elles permettent à un attaquant de provoquer une e…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-506</link>
      <description>certfr-2022-avi-506</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-506</guid>
    </item>
    <item>
      <title>EUVD-2026-202803</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-202803</link>
      <description>EUVD-2026-202803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-202803</guid>
    </item>
    <item>
      <title>fkie_cve-2022-30122</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30122</link>
      <description>&lt;p&gt;A possible denial of service vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 in the multipart parsing component of Rack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A possible denial of service vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 in the multipart parsing component of Rack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-30122</guid>
    </item>
    <item>
      <title>GHSA-hxqx-xwvh-44m2 — Denial of Service Vulnerability in Rack Multipart Parsing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hxqx-xwvh-44m2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;There is a possible denial of service vulnerability in the multipart parsing component of Rack.  This vulnerability has been assigned the CVE identifier CVE-2022-30122.&lt;/p&gt;
&lt;p&gt;Versions Affected:  &amp;gt;= 1.2
Not affected:       &amp;lt; 1.2
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted multipart POST requests can cause Rack&amp;#39;s multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.&lt;/p&gt;
&lt;p&gt;Impacted code will use Rack&amp;#39;s multipart parser to parse multipart posts.  This includes directly using the multipart parser like this:&lt;/p&gt;
&lt;p&gt;```
params = Rack::Multipart.parse_multipart(env)
```&lt;/p&gt;
&lt;p&gt;But it also includes reading POST data from a Rack request object like this:&lt;/p&gt;
&lt;p&gt;```
p request.POST # read POST data
p request.params # reads both query params and POST data
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
There are no feasible workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;There is a possible denial of service vulnerability in the multipart parsing component of Rack.  This vulnerability has been assigned the CVE identifier CVE-2022-30122.&lt;/p&gt;
&lt;p&gt;Versions Affected:  &amp;gt;= 1.2
Not affected:       &amp;lt; 1.2
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted multipart POST requests can cause Rack&amp;#39;s multipart parser to take much longer than expected, leading to a possible denial of service vulnerability.&lt;/p&gt;
&lt;p&gt;Impacted code will use Rack&amp;#39;s multipart parser to parse multipart posts.  This includes directly using the multipart parser like this:&lt;/p&gt;
&lt;p&gt;```
params = Rack::Multipart.parse_multipart(env)
```&lt;/p&gt;
&lt;p&gt;But it also includes reading POST data from a Rack request object like this:&lt;/p&gt;
&lt;p&gt;```
p request.POST # read POST data
p request.params # reads both query params and POST data
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
There are no feasible workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hxqx-xwvh-44m2</guid>
    </item>
    <item>
      <title>gsd-2022-30122</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-30122</link>
      <description>gsd-2022-30122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-30122</guid>
    </item>
    <item>
      <title>OESA-2022-1729 — rubygem-rack security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack&lt;/p&gt;
&lt;p&gt;Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)&#13;
&#13;
Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)&#13;
&#13;
A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;amp;lt; 2.2.3, rack &amp;amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack&lt;/p&gt;
&lt;p&gt;Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)&#13;
&#13;
Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)&#13;
&#13;
A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;amp;lt; 2.2.3, rack &amp;amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1729</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12119-1 — ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12119-1</link>
      <description>&lt;p&gt;ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12119-1</guid>
    </item>
    <item>
      <title>RHSA-2022:7242 — Red Hat Security Advisory: Satellite 6.11.4 Async Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7242</link>
      <description>&lt;p&gt;rubygem-rack: crafted multipart POST request may cause a DoS rubygem-tzinfo: arbitrary code execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-rack: crafted multipart POST request may cause a DoS rubygem-tzinfo: arbitrary code execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7242</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:2192-1 — Security update for rubygem-rack</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:2192-1</link>
      <description>&lt;p&gt;Security update for rubygem-rack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-rack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:2192-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-30122</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30122</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:Pro:16.04:LTS: ruby-rack, Ubuntu:Pro:18.04:LTS: ruby-rack, Ubuntu:Pro:20.04:LTS: ruby-rack, Ubuntu:22.04:LTS: ruby-rack, Ubuntu:Pro:22.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;A possible denial of service vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 in the multipart parsing component of Rack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:Pro:16.04:LTS: ruby-rack, Ubuntu:Pro:18.04:LTS: ruby-rack, Ubuntu:Pro:20.04:LTS: ruby-rack, Ubuntu:22.04:LTS: ruby-rack, Ubuntu:Pro:22.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;A possible denial of service vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 in the multipart parsing component of Rack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30122</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0262 — Ruby: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0262</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0262</guid>
    </item>
  </channel>
</rss>
