CVE-2024-26141: medium-severity vulnerability in rack
Possible DoS Vulnerability with Range Header in Rack
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in Rack's Range header handling allows attackers to craft special requests that trick the server into sending extremely large responses, overwhelming it and making it unavailable to legitimate users.
The vulnerability exists in Rack::File middleware and Rack::Utils.byte_ranges methods where maliciously crafted Range headers bypass proper validation, causing excessive memory allocation and network bandwidth consumption. This affects Rails applications and other Rack-based servers, leading to denial of service when processing the unexpectedly large responses.
In the same product, most dangerous first.