CVE-2025-59830Disclosure(rack / rack)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rack

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rack

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-05: 1Technical Details · 2026-04-05: 104-05
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Disclosure

    A `Rack` vulnerability (CVE-2025-59830) allows `params_limit` bypass in `Rack::QueryParser` via semicolon-separated parameters. Review `Rack` configurations for potential DoS risks. #infosec #webdev #security https://www.pulsepatch.io/posts/cve-2025-59830-rack-queryparser-bypass

    Post summary

    The post announces CVE-2025-59830 as a Rack::QueryParser params_limit bypass, recommending configuration review for potential DoS.

    00000239
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprackrack-ruby-

Explore more