Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is used typically used in multipart parsing. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.
Created rubygem-rack tracking bugs for this issue: Affects: epel-8 [bug 2164715] Affects: fedora-all [bug 2164716]