PT-2025-41595 · Nginx+11 · Nginx+11

Pirikara

·

Published

2025-10-10

·

Updated

2026-04-09

·

CVE-2025-61919

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rack versions prior to 2.2.20 Rack versions prior to 3.1.18 Rack versions prior to 3.2.3
Description Rack is a modular Ruby web server interface. In versions prior to 2.2.20, 3.1.18, and 3.2.3, the Rack::Request#POST method reads the entire request body into memory when handling Content-Type: application/x-www-form-urlencoded requests without enforcing a length or cap. This can lead to a denial of service (DoS) through memory exhaustion if an attacker sends a large request body. The vulnerable code calls rack.input.read(nil) which allows unbounded reads of application/x-www-form-urlencoded bodies.
Recommendations Upgrade to Rack version 2.2.20 to address the issue. Upgrade to Rack version 3.1.18 to address the issue. Upgrade to Rack version 3.2.3 to address the issue. Enforce strict maximum body size at the proxy or web server layer, such as using client max body size in Nginx or LimitRequestBody in Apache.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:19719
ALSA-2025:20962
ALSA-2025:21036
ALSA-2025_19719
ALSA-2025_20962
BDU:2025-13874
CESA-2025_19719
CLEANSTART-2026-GE08280
CLEANSTART-2026-IW08736
CLEANSTART-2026-RZ30606
CVE-2025-61919
DLA-4357-1
DSA-6048-1
GHSA-6XW4-3V39-52MM
INFSA-2025_19512
INFSA-2025_19719
INFSA-2025_20962
MGASA-2025-0334
OPENSUSE-SU-2025:15642-1
OPENSUSE-SU-2026:10286-1
OPENSUSE-SU-2026:20025-1
RHSA-2025:19512
RHSA-2025:19513
RHSA-2025:19647
RHSA-2025:19719
RHSA-2025:19733
RHSA-2025:19734
RHSA-2025:19736
RHSA-2025:19800
RHSA-2025:19948
RHSA-2025:20962
RHSA-2025:21036
RHSA-2025_19512
RHSA-2025_19719
RHSA-2025_20962
SUSE-SU-2025:4273-1
SUSE-SU-2026:20091-1
SUSE-SU-2026:20093-1
USN-7960-1

Affected Products

Almalinux
Apache
Centos
Debian
Linuxmint
Nginx
Rack
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu