Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-25126

40
FAUCET Score

CVE-2024-25126 is a denial-of-service vulnerability affecting Rack, a Ruby web server interface, and its Debian distributions. Carefully crafted content type headers can trigger a ReDoS (Regular Expression Denial of Service) attack, causing the media type parser to consume excessive resources. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely without authentication, leading to a complete loss of availability for affected systems. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.4, < 2.2.8.1CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
>= 3.0.0, < 3.0.9.1CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
35.38%
Probability of exploitation in next 30 days
EPSS Percentile
98.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3538 is in the 97th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: pcs-0:0.10.12-6.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: pcs-0:0.10.15-4.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.7-2.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: pcs-0:0.11.1-10.el9_0.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: pcs-0:0.11.4-7.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.15 for RHEL 8Fixed in: rubygem-rack-0:2.2.8.1-1.el8sat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs-0:0.10.18-2.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: pcs-0:0.10.4-6.el8_2.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: pcs-0:0.10.4-6.el8_2.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: pcs-0:0.10.8-1.el8_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: pcs-0:0.10.8-1.el8_4.5
View patch
rubygemspatch availablevia ghsa
Product: rackFixed in: 2.2.8.1
rubygemspatch availablevia ghsa
Product: rackFixed in: 3.0.9.1
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-system-container
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-backend-container
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-zync-container

Vendor Advisories (2)

rubygemsGHSA-22f2-v57c-j9cxmedium

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

Feb 28, 2024
redhatCVE-2024-25126Moderate

rubygem-rack: Denial of Service Vulnerability in Rack Content-Type Parsing

Feb 22, 2024

References

discuss.rubyonrails.org / t/denial-of-service-vulnerability-in-rack-content-type-parsing/84941
ExploitVendor Advisory
github.com / rack/rack/commit/6efb2ceea003c4b195815a614e00438cbd543462
Patch
github.com / rack/rack/commit/d9c163a443b8cadf4711d84bd2c58cb9ef89cf49
Patch
github.com / rack/rack/security/advisories/GHSA-22f2-v57c-j9cx
ExploitVendor Advisory
github.com / rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2024-25126.yml
ExploitThird Party Advisory
lists.debian.org / debian-lts-announce/2024/04/msg00022.html
Mailing List
security.netapp.com / advisory/ntap-20240510-0005
Third Party Advisory