CVE-2023-27539: Medium severity redhat/rubygem-rack vulnerability
Carefully crafted input can cause header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector.
Other sources
There is a denial of service vulnerability in the header parsing component of Rack.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-27539?
CVE-2023-27539 is a denial of service vulnerability in the header parsing component of Rack.
Which versions of Rack are affected by CVE-2023-27539?
Versions >= 2.0.0 of Rack are affected by CVE-2023-27539.
How can I fix CVE-2023-27539?
You can fix CVE-2023-27539 by upgrading to fixed versions 2.2.6.4 or 3.0.6.1 of Rack.
What is the severity of CVE-2023-27539?
CVE-2023-27539 has a severity level of high.
Where can I find more information about CVE-2023-27539?
You can find more information about CVE-2023-27539 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-27539), [Ruby Advisory Database](https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2023-27539.yml).