CVE-2025-46727
Last modified
CVE-2025-46727 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. The vulnerability arises because `Rack::QueryParser` iterates over each `&`-separated key-value pair and adds it to a Hash without enforcing an upper bound on the total number of parameters. This allows an attacker to send a single request containing hundreds of thousands (or more) of parameters, which consumes excessive memory and CPU during parsing. An attacker can trigger denial of service by sending specifically crafted HTTP requests, which can cause memory exhaustion or pin CPU resources, stalling or crashing the Rack server. This results in full service disruption until the affected worker is restarted. Versions 2.2.14, 3.0.16, and 3.1.14 fix the issue. Some other mitigations are available. One may use middleware to enforce a maximum query string size or parameter count, or employ a reverse proxy (such as Nginx) to limit request sizes and reject oversized query strings or bodies. Limiting request body sizes and query string lengths at the web server or CDN level is an effective mitigation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rack | Rack | < 2.2.14 |
| Rack | Rack | >= 3.0.0, < 3.0.16 |
| Rack | Rack | >= 3.1.0, < 3.1.14 |
References
- https://github.com/rack/rack/security/advisories/GHSA-gjh7-p2fx-99vxMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-46727?
How severe is CVE-2025-46727?
How do I fix CVE-2025-46727?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46721nosurf is cross-site request forgery (CSRF) protection middl…6.1
- CVE-2025-46722vLLM is an inference and serving engine for large language m…7.3
- CVE-2025-46723OpenVM is a performant and modular zkVM framework built for …7.8
- CVE-2025-46724Langroid is a Python framework to build large language model…9.8
- CVE-2025-46725Langroid is a Python framework to build large language model…9.8
- CVE-2025-46726Langroid is a framework for building large-language-model-po…9.1
- CVE-2025-46728cpp-httplib is a C++ header-only HTTP/HTTPS server and clien…7.5
- CVE-2025-46729julmud/phpDVDProfiler is an adoption of the defunct phpDVDPr…2.1
- CVE-2025-4673Proxy-Authorization and Proxy-Authenticate headers persisted…6.8
- CVE-2025-46730MobSF is a mobile application security testing tool used. Ty…6.5
- CVE-2025-46731Craft is a content management system. Versions of Craft CMS …7.2
- CVE-2025-46732OpenCTI is an open source platform for managing cyber threat…5.4
Are you affected by CVE-2025-46727?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
