Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header block never terminates with the required blank line (`CRLFCRLF`). The parser keeps appending incoming bytes to memory without a size cap, allowing a remote attacker to exhaust memory and cause a denial of service (DoS). Attackers can send incomplete multipart headers to trigger high memory use, leading to process termination (OOM) or severe slowdown. The effect scales with request size limits and concurrency. All applications handling multipart uploads may be affected. Versions 2.2.19, 3.1.17, and 3.2.2 cap per-part header size (e.g., 64 KiB). As a workaround, restrict maximum request sizes at the proxy or web server layer (e.g., Nginx `client_max_body_size`).
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:19513 https://access.redhat.com/errata/RHSA-2025:19513
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:19512 https://access.redhat.com/errata/RHSA-2025:19512
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:19647 https://access.redhat.com/errata/RHSA-2025:19647
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:19719 https://access.redhat.com/errata/RHSA-2025:19719
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:19733 https://access.redhat.com/errata/RHSA-2025:19733
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:19734 https://access.redhat.com/errata/RHSA-2025:19734
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:19736 https://access.redhat.com/errata/RHSA-2025:19736
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:19800 https://access.redhat.com/errata/RHSA-2025:19800
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2025:19948 https://access.redhat.com/errata/RHSA-2025:19948
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:20962 https://access.redhat.com/errata/RHSA-2025:20962
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:21036 https://access.redhat.com/errata/RHSA-2025:21036