Bug 2349699 (CVE-2025-27219) - CVE-2025-27219 CGI: Denial of Service in CGI::Cookie.parse
Summary: CVE-2025-27219 CGI: Denial of Service in CGI::Cookie.parse
Keywords:
Status: NEW
Alias: CVE-2025-27219
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2357516
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-03-04 00:01 UTC by OSIDB Bzimport
Modified: 2025-05-26 08:33 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:4063 0 None None None 2025-04-22 02:18:10 UTC
Red Hat Product Errata RHSA-2025:4487 0 None None None 2025-05-06 02:15:17 UTC
Red Hat Product Errata RHSA-2025:4488 0 None None None 2025-05-06 02:27:56 UTC
Red Hat Product Errata RHSA-2025:4493 0 None None None 2025-05-06 02:28:11 UTC
Red Hat Product Errata RHSA-2025:8131 0 None None None 2025-05-26 08:33:46 UTC

Description OSIDB Bzimport 2025-03-04 00:01:09 UTC
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

Comment 2 errata-xmlrpc 2025-04-22 02:18:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:4063 https://access.redhat.com/errata/RHSA-2025:4063

Comment 3 errata-xmlrpc 2025-05-06 02:15:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:4487 https://access.redhat.com/errata/RHSA-2025:4487

Comment 4 errata-xmlrpc 2025-05-06 02:27:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:4488 https://access.redhat.com/errata/RHSA-2025:4488

Comment 5 errata-xmlrpc 2025-05-06 02:28:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:4493 https://access.redhat.com/errata/RHSA-2025:4493

Comment 6 errata-xmlrpc 2025-05-26 08:33:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:8131 https://access.redhat.com/errata/RHSA-2025:8131


Note You need to log in before you can comment on or make changes to this bug.