CVE-2024-39316
Last modified
CVE-2024-39316 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. This vulnerability can be exploited by an attacker sending specially crafted `Accept-Encoding` or `Accept-Language` headers, causing the server to spend excessive time processing the request and leading to a Denial of Service (DoS). The fix for CVE-2024-26146 was not applied to the main branch and thus while the issue was fixed for the Rack v3.0 release series, it was not fixed in the v3.1 release series until v3.1.5. Users of versions on the 3.1 branch should upgrade to version 3.1.5 to receive the fix.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rack | Rack | >= 3.1.0, < 3.1.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-39316?
How severe is CVE-2024-39316?
How do I fix CVE-2024-39316?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-39310The Basil recipe theme for WordPress is vulnerable to Persis…5.4
- CVE-2024-39311Publify is a self hosted Web publishing platform on Rails. P…5.4
- CVE-2024-39312Botan is a C++ cryptography library. X.509 certificates can …5.3
- CVE-2024-39313toy-blog is a headless content management system implementat…5.3
- CVE-2024-39314toy-blog is a headless content management system implementat…4.7
- CVE-2024-39315Pomerium is an identity and context-aware access proxy. Prio…6.5
- CVE-2024-39317Wagtail is an open source content management system built on…4.9
- CVE-2024-39318The Ibexa Admin UI Bundle contains all the necessary parts t…5.4
- CVE-2024-39319aimeos/ai-controller-frontend is the Aimeos frontend control…5.3
- CVE-2024-3932A vulnerability classified as problematic has been found in …3.1
- CVE-2024-39320Discourse is an open source discussion platform. Prior to 3.…6.1
- CVE-2024-39321Traefik is an HTTP reverse proxy and load balancer. Versions…7.5
Are you affected by CVE-2024-39316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
