Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61770

27
FAUCET Score

CVE-2025-61770 is a high-severity denial-of-service vulnerability affecting Rack, a Ruby web server interface, in versions prior to 2.2.19, 3.1.17, and 3.2.2. Attackers can exploit this by sending a large multipart preamble without size limits, causing significant memory consumption and potential process termination due to out-of-memory conditions. The attack is network-based and low complexity, requiring no user interaction, leading to high availability impact. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.2.19CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
>= 3.1.0, < 3.1.17CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
>= 3.2.0, < 3.2.2CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.87%
Probability of exploitation in next 30 days
EPSS Percentile
55.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0087 is in the 30th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (27)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: pcs-0:0.10.15-4.el8_8.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs-0:0.10.18-2.el8_10.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: pcs-0:0.10.8-1.el8_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: pcs-0:0.10.8-1.el8_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: pcs-0:0.10.12-6.el8_6.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: pcs-0:0.10.12-6.el8_6.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: pcs-0:0.10.15-4.el8_8.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.9-2.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.10-1.el9_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: pcs-0:0.11.1-10.el9_0.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: pcs-0:0.11.4-7.el9_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: pcs-0:0.11.7-2.el9_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: pcs-0:0.12.0-3.el10_0.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: pcs-0:0.12.1-1.el10_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: pcs-0:0.9.169-3.el7_9.5
View patch
rubygemspatch availablevia ghsa
Product: rackFixed in: 3.1.17
rubygemspatch availablevia ghsa
Product: rackFixed in: 3.2.2
rubygemspatch availablevia ghsa
Product: rackFixed in: 2.2.19
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/zync-rhel7
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/zync-rhel9
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp25/zync
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/zync-rhel8
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp24/zync
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp21/zync
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp22/zync
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp26/zync

Vendor Advisories (2)

rubygemsGHSA-p543-xpfm-54cphigh

Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

Oct 7, 2025
redhatCVE-2025-61770Important

rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)

Oct 7, 2025

References

github.com / rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e
Patch
github.com / rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e
Patch
github.com / rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd
Patch
github.com / rack/rack/security/advisories/GHSA-p543-xpfm-54cp
MitigationVendor Advisory