Rack (rubygem-rack) versions 2.04 and 2.0.5 are vulnerable to a denial of service due to incorrect buffer size in the multipart parser. Carefully crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
External Reference:
https://groups.google.com/forum/#!msg/rubyonrails-security/Ux-YkfuVTg/xhvYAmp6AAAJ