CVE-2024-26142: Rails possible ReDoS vulnerability in Accept header parsing in Action Dispatch
Possible ReDoS vulnerability in Accept header parsing in Action Dispatch
There is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability has been assigned the CVE identifier CVE-2024-26142.
Versions Affected: >= 7.1.0, < 7.1.3.1 Not affected: < 7.1.0 Fixed Versions: 7.1.3.1
Impact ------ Carefully crafted Accept headers can cause Accept header parsing in Action Dispatch to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade or use one of the workarounds immediately.
Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.
Releases -------- The fixed releases are available at the normal locations.
Workarounds ----------- There are no feasible workarounds for this issue.
Patches ------- To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.
7-1-accept-redox.patch - Patch for 7.1 series
Credits ------- Thanks svalkanov for the report and patch!
Other sources
Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/actionpackto a version that resolves this vulnerability.Fixed in 7.1.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.1.3.1Patch 7-1-accept-redox.patch
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26142?
CVE-2024-26142 has a medium severity rating due to the potential for a ReDoS attack.
How do I fix CVE-2024-26142?
To fix CVE-2024-26142, upgrade Action Dispatch to version 7.1.3.1 or later.
Which versions are affected by CVE-2024-26142?
CVE-2024-26142 affects Action Dispatch versions from 7.1.0 to 7.1.3.
What consequences might I face if I do not address CVE-2024-26142?
If not addressed, CVE-2024-26142 may allow attackers to exploit the vulnerability, potentially causing denial of service.
Is my application vulnerable to CVE-2024-26142?
Your application is vulnerable to CVE-2024-26142 if it uses Action Dispatch versions between 7.1.0 and 7.1.3.