PT-2025-41597 · Sinatra+1 · Sinatra+1

·

CVE-2025-61921

·

Published

2025-10-08

·

Updated

2026-07-29

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sinatra versions prior to 4.2.0
Description Sinatra, a domain-specific language for creating web applications in Ruby, contains an issue where carefully crafted input can cause excessive processing time during the parsing of If-Match and If-None-Match headers. This occurs when the etag method is used to construct responses, potentially leading to a denial of service. The If-Match and If-None-Match headers are typically used in generating the ETag header value.
Recommendations Update to Sinatra version 4.2.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02917
CVE-2025-61921
GHSA-MR3Q-G2MV-MR4Q
USN-8624-1

Affected Products

Debian
Sinatra