VDB

GCVE-VVD-MAGEIA-2024-123

GCVE-VVD-MAGEIA-2024-123
Advisory Published
Vulnetix · Advisory published April 10, 2024
Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). (CVE-2024-25126) Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). (CVE-2024-26141) Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. (CVE-2024-26146)

Affected Products

VendorProductVersionsPlatforms
Mageiaruby-rack0 (affected), 2.2.8.1-1.mga9 (unaffected), 0 (affected), 2.2.8.1-1.mga9 (unaffected)
Mageiax11-data-cursor-themes0 (affected), 1.0.7-1.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›