In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:4063 https://access.redhat.com/errata/RHSA-2025:4063
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:4487 https://access.redhat.com/errata/RHSA-2025:4487
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:4488 https://access.redhat.com/errata/RHSA-2025:4488
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:4493 https://access.redhat.com/errata/RHSA-2025:4493
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:8131 https://access.redhat.com/errata/RHSA-2025:8131