Lucene search

K
cvelistHackeroneCVELIST:CVE-2018-16470
HistoryNov 13, 2018 - 11:00 p.m.

CVE-2018-16470

2018-11-1323:00:00
CWE-400
hackerone
www.cve.org
1

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.0%

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

CNA Affected

[
  {
    "product": "Rack",
    "vendor": "Rack",
    "versions": [
      {
        "status": "affected",
        "version": "2.0.6"
      }
    ]
  }
]

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.0%