Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38916
HistoryJan 19, 2023 - 2:08 a.m.

Regular Expression Denial Of Service (ReDoS)

2023-01-1902:08:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
regular expression
denial of service
redos
range header parsing
vulnerability
software

EPSS

0.002

Percentile

52.1%

rack is vulnerable to Regular Expression Denial of Service (ReDoS) attacks. The vulnerability exists in the Range header parsing component of the library, which allows an attacker to significantly slow down the processing via passing a carefully crafted input.