PT-2025-41597 · Sinatra+1 · Sinatra+1
Ooooooo-Q
·
Published
2025-10-08
·
Updated
2025-10-14
·
CVE-2025-61921
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sinatra versions prior to 4.2.0
Description
Sinatra, a domain-specific language for creating web applications in Ruby, contains an issue where carefully crafted input can cause excessive processing time during the parsing of
If-Match and If-None-Match headers. This occurs when the etag method is used to construct responses, potentially leading to a denial of service. The If-Match and If-None-Match headers are typically used in generating the ETag header value.Recommendations
Update to Sinatra version 4.2.0 or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Sinatra