-
Task
-
Resolution: Unresolved
-
Major
-
None
-
None
-
None
-
False
-
-
False
-
Not Started
-
Not Started
-
Not Started
-
Not Started
-
Not Started
-
Not Started
-
-
Upgrade rack dependency to fix potential CVEs:
- CVE-2025-49007 Fix ReDoS in multipart request.
- CVE-2025-61772 Multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
- CVE-2025-61771 Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
- CVE-2025-61770 Unbounded multipart preamble buffering enables DoS (memory exhaustion)
- CVE-2025-61780 Improper handling of headers in Rack::Sendfile may allow proxy bypass.
- CVE-2025-61919 Unbounded read in Rack::Request form parsing can lead to memory exhaustion.
See release notes: https://github.com/rack/rack/blob/main/CHANGELOG.md#3119---2025-11-03
- is cloned by
-
THREESCALE-12056 Upgrade rack for apisonator - backport for 2.16
-
- To Test (QE)
-
- mentioned on