CVE-2025-61771: Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
Summary
Rack::Multipart::Parser stores non-file form fields (parts without a filename) entirely in memory as Ruby String objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) conditions and denial of service (DoS).
Details
During multipart parsing, file parts are streamed to temporary files, but non-file parts are buffered into memory:
ruby body = String.new # non-file → in-RAM buffer @mimeparts[mimeindex].body << content
There is no size limit on these in-memory buffers. As a result, any large text field—while technically valid—will be loaded fully into process memory before being added to params.
Impact
Attackers can send large non-file fields to trigger excessive memory usage. Impact scales with request size and concurrency, potentially leading to worker crashes or severe garbage-collection overhead. All Rack applications processing multipart form submissions are affected.
Mitigation
Upgrade: Use a patched version of Rack that enforces a reasonable size cap for non-file fields (e.g., 2 MiB). Workarounds: Restrict maximum request body size at the web-server or proxy layer (e.g., Nginx clientmaxbodysize). Validate and reject unusually large form fields at the application level.
Other sources
Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, Rack::Multipart::Parser stores non-file form fields (parts without a filename) entirely in memory as Ruby String objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) conditions and denial of service (DoS). Attackers can send large non-file fields to trigger excessive memory usage. Impact scales with request size and concurrency, potentially leading to worker crashes or severe garbage-collection overhead. All Rack applications processing multipart form submissions are affected. Versions 2.2.19, 3.1.17, and 3.2.2 enforce a reasonable size cap for non-file fields (e.g., 2 MiB). Workarounds include restricting maximum request body size at the web-server or proxy layer (e.g., Nginx clientmaxbodysize) and validating and rejecting unusually large form fields at the application level.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/rackto a version that resolves this vulnerability.Fixed in 3.2.2 - Upgrade
Upgrade
rubygems/rackto a version that resolves this vulnerability.Fixed in 3.1.17 - Upgrade
Upgrade
rubygems/rackto a version that resolves this vulnerability.Fixed in 2.2.19 - Upgrade
Upgrade
Rackto a version that resolves this vulnerability.Fixed in 2.2.19 - Upgrade
Upgrade
Rackto a version that resolves this vulnerability.Fixed in 3.1.17 - Upgrade
Upgrade
Rackto a version that resolves this vulnerability.Fixed in 3.2.2 - Configuration
At the web-server/proxy layer, restrict the maximum request body size using Nginx `client_max_body_size` to limit multipart payloads that could otherwise exhaust memory in Rack.
Nginx client_max_body_size = (set to an appropriate maximum smaller than what would cause OOM; workaround example provided) - Configuration
At the application level, validate and reject unusually large non-file multipart form fields (parts without a `filename`) before they are accepted/processed to prevent in-RAM buffering from causing OOM/DoS.
Rack application (multipart/form-data handling) application-level non-file form field size validation = (reject unusually large form fields)
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61771?
CVE-2025-61771 has a moderate severity level due to the potential risk of excessive memory usage from unbounded large text fields.
How do I fix CVE-2025-61771?
To fix CVE-2025-61771, upgrade Rack to version 2.2.19, 3.1.17, or 3.2.2 or later.
What versions of Rack are affected by CVE-2025-61771?
CVE-2025-61771 affects Rack versions prior to 2.2.19, 3.1.17, and 3.2.2.
What type of data does CVE-2025-61771 impact?
CVE-2025-61771 impacts non-file form fields in multipart/form-data requests stored in memory.
What is the potential exploit of CVE-2025-61771?
The potential exploit of CVE-2025-61771 lies in the denial of service through excessive memory consumption.