CVE-2015-3225

EPSS 13.3%

Rack vulnerable to Denial of Service via large parameter depth request

Published: 10/24/2017Modified: 4/28/2026
Also known as:GHSA-rgr4-9jh5-j4j6DEBIAN-CVE-2015-3225

Description

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

Affected packages (4)

References (14)