CVE-2023-27539

There is a denial of service vulnerability in the header parsing component of Rack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

10 Oct 2025, 16:31

Type Values Removed Values Added
First Time Rack rack
Rack
Debian
Debian debian Linux
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
References () https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466 - () https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466 - Vendor Advisory
References () https://github.com/advisories/GHSA-c6qg-cjj8-47qp - () https://github.com/advisories/GHSA-c6qg-cjj8-47qp - Third Party Advisory, Patch
References () https://github.com/rack/rack/commit/231ef369ad0b542575fb36c74fcfcfabcf6c530c - () https://github.com/rack/rack/commit/231ef369ad0b542575fb36c74fcfcfabcf6c530c - Patch
References () https://github.com/rack/rack/commit/ee7919ea04303717858be1c3f16b406adc6d8cff - () https://github.com/rack/rack/commit/ee7919ea04303717858be1c3f16b406adc6d8cff - Patch
References () https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html - () https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20231208-0016/ - () https://security.netapp.com/advisory/ntap-20231208-0016/ - Third Party Advisory
References () https://www.debian.org/security/2023/dsa-5530 - () https://www.debian.org/security/2023/dsa-5530 - Mailing List, Third Party Advisory
CWE NVD-CWE-noinfo

09 Jan 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
Summary
  • (es) Existe una vulnerabilidad de denegación de servicio en header parsing component de Rack.

09 Jan 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 01:15

Updated : 2025-10-10 16:31


NVD link : CVE-2023-27539

Mitre link : CVE-2023-27539

CVE.ORG link : CVE-2023-27539


JSON object : View

Products Affected

debian

  • debian_linux

rack

  • rack