CVE Database
/

CVE-2022-44570

Back to search

CVE-2022-44570

Published: Feb 9, 2023

Modified: Aug 3, 2024

PUBLISHED

Description

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

VendorProductVersions

n/a

https://github.com/rack/rack

affected
2.0.9.2, 2.1.4.2, 2.2.4.2, 3.0.0.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now