Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2023-27539
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2023-27539
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27539.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-27539
Aliases
GHSA-c6qg-cjj8-47qp
Downstream
DEBIAN-CVE-2023-27539
DLA-3392-1
DSA-5530-1
RHSA-2023:1961
RHSA-2023:1981
RHSA-2023:2652
RHSA-2023:3082
RHSA-2023:3403
RHSA-2023:6818
SUSE-SU-2023:1685-1
SUSE-SU-2023:1869-1
UBUNTU-CVE-2023-27539
USN-6905-1
USN-7036-1
openSUSE-SU-2024:12789-1
openSUSE-SU-2024:12805-1
openSUSE-SU-2024:13726-1
openSUSE-SU-2024:13727-1
openSUSE-SU-2025:14811-1
openSUSE-SU-2025:14875-1
Related
ALSA-2023:2652
ALSA-2023:3082
MGASA-2024-0042
RLSA-2023:2652
RLSA-2023:3082
RLSA-2023:6818
SUSE-SU-2023:1685-1
SUSE-SU-2023:1869-1
USN-6689-1
openSUSE-SU-2024:12789-1
openSUSE-SU-2024:12805-1
openSUSE-SU-2024:13726-1
openSUSE-SU-2024:13727-1
openSUSE-SU-2025:14811-1
openSUSE-SU-2025:14875-1
Published
2025-01-09T01:15:07Z
Modified
2025-09-24T12:03:16.042930Z
Summary
[none]
Details
There is a denial of service vulnerability in the header parsing component of Rack.
References
https://github.com/advisories/GHSA-c6qg-cjj8-47qp
https://security.netapp.com/advisory/ntap-20231208-0016/
https://www.debian.org/security/2023/dsa-5530
https://github.com/rack/rack/commit/231ef369ad0b542575fb36c74fcfcfabcf6c530c
https://github.com/rack/rack/commit/ee7919ea04303717858be1c3f16b406adc6d8cff
https://discuss.rubyonrails.org/t/cve-2023-27539-possible-denial-of-service-vulnerability-in-racks-header-parsing/82466
https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html
Affected packages
Git
/
github.com/rack/rack
Affected ranges
Type
GIT
Repo
https://github.com/rack/rack
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
231ef369ad0b542575fb36c74fcfcfabcf6c530c
Fixed
ee7919ea04303717858be1c3f16b406adc6d8cff
Affected versions
0.*
0.1
0.2
0.3
1.*
1.0
1.1
1.2
1.2.1
1.3.0
1.3.0.beta
1.3.0.beta2
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.0.beta
1.6.0.beta2
2.*
2.0.0
2.0.0.alpha
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.2.3
2.2.3.1
2.2.4
3.*
3.0.0
3.0.0.beta1
3.0.0.rc1
v2.*
v2.2.1
v2.2.2
v2.2.5
v2.2.6
v2.2.6.1
v2.2.6.2
v2.2.6.3
v3.*
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.4.1
v3.0.4.2
v3.0.5
v3.0.6
CVE-2023-27539 - OSV