CVE-2023-27539

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 9, 2025

Summary

CVE-2023-27539 is a newly identified denial of service vulnerability that affects the header parsing component of Rack, an open-source web server for Ruby. Maliciously crafted HTTP headers can cause the application to consume excessive system resources, leading to a denial of service condition. The vulnerability can be exploited by sending specially crafted requests to the affected Rack application, potentially causing service disruptions or crashes. Users of Rack are strongly advised to apply the available patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share