Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61772

27
FAUCET Score

CVE-2025-61772 is a denial-of-service vulnerability affecting Rack, a Ruby web server interface, in versions prior to 2.2.19, 3.1.17, and 3.2.2. A remote attacker can exhaust memory by sending incomplete multipart headers, causing process termination or severe slowdown. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low attack complexity, and high impact on availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.2.19CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
>= 3.1.0, < 3.1.17CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
>= 3.2.0, < 3.2.2CPE matchmatch criteria
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.87%
Probability of exploitation in next 30 days
EPSS Percentile
55.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0087 is in the 30th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (56)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: pcs-0:0.10.12-6.el8_6.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: pcs-0:0.10.12-6.el8_6.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: pcs-0:0.10.15-4.el8_8.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: pcs-0:0.10.15-4.el8_8.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.9-2.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.10-1.el9_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: pcs-0:0.11.1-10.el9_0.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: pcs-0:0.11.4-7.el9_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: pcs-0:0.10.8-1.el8_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: pcs-0:0.11.7-2.el9_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: pcs-0:0.12.1-1.el10_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs-0:0.10.18-2.el8_10.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: pcs-0:0.10.8-1.el8_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: pcs-0:0.12.0-3.el10_0.3
View patch
rubygemspatch availablevia ghsa
Product: rackFixed in: 3.1.17
rubygemspatch availablevia ghsa
Product: rackFixed in: 3.2.2
rubygemspatch availablevia ghsa
Product: rackFixed in: 2.2.19
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rhel10/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: ubi10/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: rhel8/ruby-25
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: rhel8/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: ubi8/ruby-25
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: ubi8/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/ruby-30
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-redis
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/cluster-logging-operator-bundle
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/cluster-logging-rhel9-operator
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/eventrouter-rhel9
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/fluentd-rhel8
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/fluentd-rhel9
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/log-file-metric-exporter-rhel9
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/logging-view-plugin-rhel9
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/vector-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp21/zync
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp22/zync
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp24/zync
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp25/zync
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp26/zync
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/zync-rhel7
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/zync-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/zync-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-zync-container
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-cinder-volume
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-haproxy
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-manila-share
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-mariadb
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-ovn-northd
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-rabbitmq
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: rhosp13/openstack-cinder-backup
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/ruby-33
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ubi9/ruby-30
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ubi9/ruby-31
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ubi9/ruby-33
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/ruby-31

Vendor Advisories (2)

rubygemsGHSA-wpv5-97wm-hp9chigh

Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)

Oct 7, 2025
redhatCVE-2025-61772Moderate

rack: Rack memory exhaustion denial of service

Oct 7, 2025

References

github.com / rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e
Patch
github.com / rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e
Patch
github.com / rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd
Patch
github.com / rack/rack/security/advisories/GHSA-wpv5-97wm-hp9c
MitigationVendor Advisory